CVE-2026-88891

Source
https://cve.org/CVERecord?id=CVE-2026-88891
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88891.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88891
Aliases
  • GHSA-f9rx-pxgw-c6rg
Published
2026-09-10T13:05:39Z
Modified
2026-10-04T02:47:02Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenPanel through 2.3.0 Read-Only Access Level Enforcement Bypass via Mutations
Details

OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-269"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88891.json"
}
References

Affected packages

Git / github.com/openpanel-dev/openpanel

Affected ranges

Type
GIT
Repo
https://github.com/openpanel-dev/openpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.3.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

Other
api
dashboard
self-hosting
worker
v2.*
v2.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88891.json"