Junglewise Threat Intelligence

CVE-2026-93983: OpenPanel SQL injection in ClickHouse property key filtering

CVE-2026-93983 · Severity: medium · CVSS 5 · Published 2026-09-19

Technologies: OpenPanel. Vendors: OpenPanel.

Executive brief

OpenPanel is an open-source analytics platform that processes and visualizes user event data. An authenticated user with read access to analytics charts can inject malicious SQL commands through filter names to bypass project isolation boundaries and view metrics and event counts from other customers' projects on the same instance, exposing confidential business analytics data.

Technical details

OpenPanel's chart service fails to properly escape property key values when constructing ClickHouse SQL queries, allowing SQL injection via the non-wildcard branch of getSelectPropertyKey(). An authenticated attacker can inject boolean SQL terms (e.g., OR 1=1) through series[].filters[].name to override the project_id constraint, reaching the shared ClickHouse multi-tenant backend over the network. The vulnerability is read-only and requires prior authentication but enables cross-project data leakage.

Affected products

  • OpenPanel OpenPanel through commit bad75bdd

Timeline

  • 2026-09-19: disclosed

References

Related threats