CVE-2026-88893 Details
Description
OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.
A vulnerability exists in OpenPanel's share lookup procedures, which fail to properly validate access controls. This flaw allows unauthenticated callers to access password hashes and protected report definitions. Specifically, attackers with a share link can obtain argon2id password hashes and detailed report configurations, including event names, filters, and breakdown dimensions. Such information can be exploited for offline password cracking and business intelligence theft. The vulnerability affects OpenPanel versions 0 and above.
To address this vulnerability, share lookup procedures should be modified to include explicit projections that exclude the password column from the response. Additionally, access controls should be enforced in the 'share.report' procedure to ensure that only authorized users can access protected content.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-7gv7-c464-9wh8 | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/openpanel-unauthenticated-share-lookup-information-disclosure | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenPanel | >= 0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | [email protected] |
Volerion