Junglewise Threat Intelligence

CVE-2026-85611: OpenPanel cross-tenant broken object level authorization in report procedures

CVE-2026-85611 · Severity: medium · CVSS 6.4 · Published 2026-09-04

Technologies: OpenPanel. Vendors: OpenPanel.

Executive brief

OpenPanel is a web analytics and dashboard platform that allows organizations to create and manage reports. Two API procedures (report.getLayouts and report.resetLayout) fail to properly verify that a user has access to a specific dashboard before reading or deleting its configuration. An authenticated attacker can guess another organization's dashboard name and use it to read sensitive report definitions or permanently delete dashboard layouts belonging to other organizations, bypassing multi-tenant isolation controls.

Technical details

This is a cross-tenant broken object level authorization (BOLA) vulnerability in two tRPC procedures within the OpenPanel API. The procedures accept a caller-supplied projectId and dashboardId, verify the caller has access to the projectId, but then query the database by dashboardId alone without binding it back to the supplied project. This allows an authenticated attacker from one organization to access dashboards belonging to other organizations by supplying their own (access-checked) projectId alongside a victim organization's guessable dashboardId. Dashboard IDs are human-readable slugs derived from dashboard names (e.g., "revenue-overview"), making them enumerable. An attacker needs only a basic authenticated account in any organization—no elevated privileges required. The vulnerability affects report.getLayouts (read) and report.resetLayout (mutation, which destructively deletes layout data). Patching was incomplete; a prior commit added tenant scoping to sibling procedures (report.list and report.get) but omitted it from getLayouts and resetLayout. A fix is available in version 2.3.0 and later.

Affected products

  • OpenPanel OpenPanel before 2.3.0

Timeline

  • 2026-08-20: disclosed: GitHub security advisory GHSA-g3xf-pqfp-22v7 published
  • 2026-09-04: advisory: NVD entry published for CVE-2026-85611
  • 2026-09-04: patched: Fixed in version 2.3.0

References

Related threats