Executive brief
OpenPanel is a web-based analytics and reporting platform that allows users to share dashboards and reports via links, optionally protected with passwords. The vulnerability allows unauthenticated attackers who possess a share link to retrieve sensitive information including argon2id password hashes and complete report configurations (event names, filters, breakdown dimensions). This enables offline password cracking attacks and theft of business intelligence, defeating the security controls the owner intended to put in place.
Technical details
The vulnerability is an access control bypass in three unauthenticated TRPC procedures (share.report, share.dashboard, share.overview) that return share records without proper filtering. The root cause is use of Prisma's findUnique without a top-level select statement, combined with object spreading that exposes all scalar columns including the password hash. The share.report procedure has an additional defect: it unconditionally returns the full report configuration via transformReport() without validating the share.public flag or checking password authorization, returning hasAccess: false while leaking the protected configuration. An attacker with a share URL can exploit this over the network with no authentication or user interaction required. Chart data itself remains protected by validateShareAccess middleware, but the share record credentials and report metadata leak. No patch has been released as of the advisory date.
Affected products
- Openpanel-dev OpenPanel >= 0
Timeline
- 2026-08-26: disclosed: GitHub Security Advisory GHSA-7gv7-c464-9wh8 published
- 2026-09-10: advisory: CVE-2026-88893 published on NVD