CVE-2026-88891
OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.
| CWE | CWE-269 |
| Vendor | openpanel-dev |
| Product | openpanel |
| Published | Sep 10, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for openpanel-dev openpanel
Be the first to know when new high vulnerabilities affecting openpanel-dev openpanel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High
Affected Versions
Openpanel-dev / openpanel
0 โค worker
References
Credits
๐ 5ud0er