Vulnerability Description
OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-g3xf-pqfp-22
- https://www.vulncheck.com/advisories/openpanel-before-2.3.0-cross-tenant-bola-vi
- https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-g3xf-pqfp-22
FAQ
What is CVE-2026-85611?
CVE-2026-85611 is a vulnerability with a CVSS score of 6.4 (MEDIUM). OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to t...
How severe is CVE-2026-85611?
CVE-2026-85611 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-85611?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.