Junglewise Threat Intelligence

CVE-2026-88891: OpenPanel privilege escalation in mutation resolvers via missing access level validation

CVE-2026-88891 · Severity: high · CVSS 8.3 · Published 2026-09-10

Technologies: OpenPanel. Vendors: OpenPanel.

Executive brief

OpenPanel is an analytics and reporting platform that allows organization administrators to grant read-only access to team members who should only view dashboards and reports without making changes. Due to missing access level validation in 26 of 29 mutating procedures, read-only members can actually modify, delete, and publish reports and dashboards, schedule entire projects for deletion, and change alerting rules. This breaks the trust boundary intended by the read-only access level assignment and exposes sensitive analytics to unauthorized publication.

Technical details

This is a privilege escalation vulnerability in OpenPanel's tRPC mutation resolvers caused by incomplete authorization checks. The getProjectAccess helper returns an access object with a level property (read/write/admin), but 26 of 29 mutations gate access by testing only truthiness of the access object—allowing read-level members to pass checks intended for higher privileges. Only 3 mutations (import.create, import.delete, import.retry) correctly validate the access.level property. The vulnerable mutations span critical operations: project.delete schedules deletion within 24 hours, share.createReport and share.createDashboard can publish private analytics publicly, and report.delete/dashboard.delete permanently destroy work. The precondition is an explicit read-only project access grant from an organization admin; no authentication bypass or additional privileges are required. No patched versions are currently available according to the advisory.

Affected products

  • OpenPanel OpenPanel all versions

Timeline

  • 2026-08-26: disclosed
  • 2026-09-10: advisory

References

Related threats