Vulnerability Description
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, but nothing verified that the supplied dashboardId belonged to that project, and getReportsByDashboardId in packages/db/src/services/reports.service.ts selects reports by dashboardId alone with no project scoping. An authenticated user could therefore pair a projectId from their own organization, which satisfies the middleware, with a dashboardId belonging to another organization and receive every report in that dashboard. A correctly scoped helper, listReportsCore, already existed in the same service file and resolves the dashboard through getDashboardById(dashboardId, projectId) before returning reports, but the router did not use it.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Openpanel-dev/openpanel
- https://github.com/Openpanel-dev/openpanel/blob/e8a0602cda5a4d4b463f11d298a1b078
- https://github.com/Openpanel-dev/openpanel/commit/0a51b6805eed0b3da8376175acd5fa
- https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-3q95-vc6f-vc
- https://www.vulncheck.com/advisories/openpanel-report-list-queries-reports-by-an
FAQ
What is CVE-2026-77769?
CVE-2026-77769 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc...
How severe is CVE-2026-77769?
CVE-2026-77769 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-77769?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.