OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries. | |
| Title | OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T11:30:07.432Z
Updated: 2026-09-04T18:02:43.598Z
Reserved: 2026-09-04T11:01:47.585Z
Link: CVE-2026-85611
Updated: 2026-09-04T18:02:38.849Z
Status : Deferred
Published: 2026-09-04T12:17:24.593
Modified: 2026-09-08T20:18:59.270
Link: CVE-2026-85611
No data.