๐Ÿ” CVE Alert

CVE-2026-88891

HIGH 8.3

OpenPanel Read-Only Access Level Enforcement Bypass via Mutations

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.

CWE CWE-269
Vendor openpanel-dev
Product openpanel
Published Sep 10, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openpanel-dev openpanel

Be the first to know when new high vulnerabilities affecting openpanel-dev openpanel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High

Affected Versions

Openpanel-dev / openpanel
0 โ‰ค worker

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-f9rx-pxgw-c6rg vulncheck.com: https://www.vulncheck.com/advisories/openpanel-read-only-access-level-enforcement-bypass-via-mutations

Credits

๐Ÿ” 5ud0er