Status: UPDATED
| Advisory ID: CVE-2026-88890
Key Details
| CVE | CVE-2026-88890 |
| CVSS Score / Version | 8.5 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is none; availability impact is low. |
| Affected products | Openpanel-dev openpanel |
| Classified as | CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques. (NVD)
What to Do
Monitor Openpanel-dev's web page for any future patch releases.
References