Impact
OpenPanel's share lookup functionality fails to enforce access controls, causing it to return Argon2id password hashes and detailed report definitions to callers who provide only a share link. The disclosed data includes strong credential hashes and business‑relevant configuration details such as event names, filters and breakdown dimensions, enabling attackers to crack passwords offline and extract sensitive business intelligence.
Affected Systems
All builds of OpenPanel are potentially affected, as no specific version gating is provided. Administrators should verify whether their deployment exposes the share lookup endpoint and determine if a remedial update is available from Openpanel‑dev. If a fix is not yet released, consider disabling the share lookup feature or imposing authentication requirements.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is classified as high‑severity. Although the EPSS score is not available, the risk remains significant due to the ease of triggering the flaw via an unauthenticated share link. The lack of a KEV listing does not diminish the threat; attackers can freely abuse the information disclosure to facilitate credential theft and compromise of confidential reports.
OpenCVE Enrichment