← All Advisories

CVE-2026-88890

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-88890

Key Details

CVECVE-2026-88890
CVSS Score / Version8.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is none; availability impact is low.
Affected productsOpenpanel-dev openpanel
Classified asCWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Openpanel-devopenpanel
SubsystemsGeneral OT
SectorsMultiple

What to Know

OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques. (NVD)

What to Do

Monitor Openpanel-dev's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-88890
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-88890