OpenPanel 在提交 cd24bb8 之前的版本中存在一个 SQL 注入漏洞,位于分析过滤器构建器中。该构建器在将 过滤器列标识符插入 ClickHouse 的 WHERE 子句前未对其进行校验。拥有项目范围读取权限或 root 导出权限的已认证攻击者,可通过盲式布尔预言技术(blind boolean oracle)注入任意 ClickHouse SQL,从而绕过项目隔离,读取其他组织的分析数据及个人身份信息(PII)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ cd24bb8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88891 | 8.3 HIGH | OpenPanel Read-Only Access Level Enforcement Bypass via Mutations |
| CVE-2026-88893 | 7.5 HIGH | OpenPanel Unauthenticated Share Lookup Information Disclosure |
| CVE-2026-88892 | 5.0 MEDIUM | OpenPanel SSRF via Unguarded Importer File URL Fetch |
No comments yet