Description
Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross-project Resource Exposure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated user with only viewer permissions to supply a different project identifier in the query parameters of project-scoped list endpoints such as /api/v1/projects/{project}/dashboards and /api/v1/datasources. The API then selects dashboards, data sources, and variables for the supplied project without checking whether the caller is authorized to view that project. The result is that complete resource specifications belonging to other projects are exposed to users who should not have access, violating confidentiality and tenant isolation as defined by CWE‑639.

Affected Systems

Open‑source observability dashboard and visualization platform Perses is affected. Any instance running a version earlier than 0.54.0‑beta.3, including 0.53.x and other older releases, contains the flaw because the authorization check was added only in 0.54.0‑beta.3.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the fact that an attacker only needs viewer credentials to trigger the bypass makes the risk substantial. The vulnerability is currently not listed in CISA’s KEV catalog. Attackers can exploit the flaw by authenticating with any viewer account, appending a different project ID to the API query, and retrieving resources from other projects. Immediate remediation is advised to prevent cross-project data leakage.

Generated by OpenCVE AI on September 19, 2026 at 11:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Perses to version 0.54.0‑beta.3 or newer, which implements the missing authorization check for project‑scoped endpoints.
  • Re‑audit user permissions in each project to ensure that viewer accounts only have access to the projects they are intended to view.
  • If upgrading immediately is not possible, temporarily restrict the project‑scoped list endpoints to authenticated users who own the requested project by implementing a server‑side check or using a firewall rule that blocks requests containing a mismatched project identifier.

Generated by OpenCVE AI on September 19, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cjgj-2fwf-4c2w Perses's project query parameter authorization bypass exposes cross-project resources
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Perses
Perses perses
Vendors & Products Perses
Perses perses

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.
Title Perses project query parameter authorization bypass exposes cross-project resources
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T19:50:33.901Z

Reserved: 2026-07-16T21:37:45.768Z

Link: CVE-2026-63458

cve-icon Vulnrichment

Updated: 2026-09-18T19:50:29.857Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:17:10.643

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-63458

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T17:32:54Z

Links: CVE-2026-63458 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:04:23Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key