Impact
OpenPanel’s access control mechanism fails to enforce the read‑only project access level on 26 of 29 mutation procedures. This authorization flaw, identified as CWE‑269, lets users who are only entitled to read privileges change, delete, or publish project data, thereby compromising data integrity and confidentiality.
Affected Systems
The affected product is OpenPanel from Openpanel‑dev. All installations that have not yet applied the vendor’s remediation are vulnerable; specific version information is not listed in the advisory.
Risk and Exploitability
The CVSS score of 7.2 places this vulnerability in the high severity range. An attacker requires only legitimate read‑only access to an account to abuse the bug, typically through a mutation resolver exposed by the application. No privilege escalation is needed. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the potential for data loss and accidental disclosure warrants immediate attention.
OpenCVE Enrichment