OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques. | |
| Title | OpenPanel SQL Injection via unvalidated profile filter column identifier | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-10T13:05:38.816Z
Updated: 2026-09-10T13:05:38.816Z
Reserved: 2026-09-10T11:28:50.296Z
Link: CVE-2026-88890
No data.
Status : Deferred
Published: 2026-09-10T14:17:18.200
Modified: 2026-09-10T15:13:07.090
Link: CVE-2026-88890
No data.