OpenPanel 在 29 个变更(mutating)过程中,有 26 个未能强制执行“只读”项目访问级别,导致具有只读权限的成员能够修改、删除并发布项目数据。拥有显式只读访问权限的攻击者可以利用变更解析器(mutation resolvers)中缺失的访问级别验证机制,执行以下操作:删除报告和仪表盘、将整个项目标记为待删除、将私有分析数据发布到公开分享链接,以及修改告警规则。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ worker | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88890 | 8.5 HIGH | OpenPanel SQL Injection via unvalidated profile filter column identifier |
| CVE-2026-88893 | 7.5 HIGH | OpenPanel Unauthenticated Share Lookup Information Disclosure |
| CVE-2026-88892 | 5.0 MEDIUM | OpenPanel SSRF via Unguarded Importer File URL Fetch |
No comments yet