Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88891— OpenPanel Read-Only Access Level Enforcement Bypass via Mutations

Quick assessment

Affected
Openpanel-dev openpanel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenPanel 在 29 个变更(mutating)过程中,有 26 个未能强制执行“只读”项目访问级别,导致具有只读权限的成员能够修改、删除并发布项目数据。拥有显式只读访问权限的攻击者可以利用变更解析器(mutation resolvers)中缺失的访问级别验证机制,执行以下操作:删除报告和仪表盘、将整个项目标记为待删除、将私有分析数据发布到公开分享链接,以及修改告警规则。

CVSS 8.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88891

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
Source: CVE Program / CVE List V5
Vulnerability Description
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Openpanel-dev openpanel 0 ~ worker -

II. Public POCs for CVE-2026-88891

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88891

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88891 (2)

Same Patch Batch · Openpanel-dev · 2026-09-10 · 4 CVEs total

CVE-2026-88890 8.5 HIGH OpenPanel SQL Injection via unvalidated profile filter column identifier
CVE-2026-88893 7.5 HIGH OpenPanel Unauthenticated Share Lookup Information Disclosure
CVE-2026-88892 5.0 MEDIUM OpenPanel SSRF via Unguarded Importer File URL Fetch

IV. Related Vulnerabilities

V. Comments for CVE-2026-88891

No comments yet


Leave a comment