OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 14:17
Updated : 2026-09-10 15:17
NVD link : CVE-2026-88893
Mitre link : CVE-2026-88893
CVE.ORG link : CVE-2026-88893
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
