Executive brief
OpenPanel is an open-source analytics platform that allows users to view reports organized by dashboards and projects. An authenticated user could request reports from a dashboard in another organization by providing their own projectId (which passes validation) paired with a dashboardId from a different organization, bypassing the project-scoping check and exposing all reports in that dashboard.
Technical details
The report.list procedure in packages/trpc/src/routers/report.ts performs an incomplete authorization check. The enforceAccess middleware validates that the supplied projectId belongs to the authenticated user's organization, but the code does not verify that the supplied dashboardId belongs to the same project. The underlying getReportsByDashboardId function queries reports by dashboardId alone without project scoping. An authenticated attacker can exploit this by combining a valid projectId from their own organization with a dashboardId from another organization to retrieve all reports in that dashboard. A correctly scoped helper function (listReportsCore) already exists in the codebase but was not used by the router.
Affected products
- OpenPanel OpenPanel <UNKNOWN>
Timeline
- 2026-08-21: disclosed: CVE-2026-77769 published