Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques. | |
| Title | OpenPanel SQL Injection via unvalidated profile filter column identifier | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-10T13:05:38.816Z
Reserved: 2026-09-10T11:28:50.296Z
Link: CVE-2026-88890
No data.
Status : Deferred
Published: 2026-09-10T14:17:18.200
Modified: 2026-09-10T15:13:07.090
Link: CVE-2026-88890
No data.
OpenCVE Enrichment
Updated: 2026-09-10T15:00:15Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')