OpenPanel 的共享查找过程未能验证访问控制,导致未认证的调用者可以获取密码哈希值和受保护报告定义。拥有共享链接的攻击者能够检索 argon2id 密码哈希值以及完整的报告配置(包括事件名称、过滤器和分解维度),从而用于离线密码破解和商业情报窃取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ worker | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88890 | 8.5 HIGH | OpenPanel SQL Injection via unvalidated profile filter column identifier |
| CVE-2026-88891 | 8.3 HIGH | OpenPanel Read-Only Access Level Enforcement Bypass via Mutations |
| CVE-2026-88892 | 5.0 MEDIUM | OpenPanel SSRF via Unguarded Importer File URL Fetch |
No comments yet