Description
OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.
Published: 2026-09-10
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Sensitive Information Exposure
Action: Immediate Patch
AI Analysis

Impact

OpenPanel's share lookup functionality fails to enforce access controls, causing it to return Argon2id password hashes and detailed report definitions to callers who provide only a share link. The disclosed data includes strong credential hashes and business‑relevant configuration details such as event names, filters and breakdown dimensions, enabling attackers to crack passwords offline and extract sensitive business intelligence.

Affected Systems

All builds of OpenPanel are potentially affected, as no specific version gating is provided. Administrators should verify whether their deployment exposes the share lookup endpoint and determine if a remedial update is available from Openpanel‑dev. If a fix is not yet released, consider disabling the share lookup feature or imposing authentication requirements.

Risk and Exploitability

With a CVSS score of 8.7, the vulnerability is classified as high‑severity. Although the EPSS score is not available, the risk remains significant due to the ease of triggering the flaw via an unauthenticated share link. The lack of a KEV listing does not diminish the threat; attackers can freely abuse the information disclosure to facilitate credential theft and compromise of confidential reports.

Generated by OpenCVE AI on September 10, 2026 at 14:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to the version that addresses the improper access control in share lookups.
  • Restrict or disable public share link access; enforce authenticated requests for any lookup operation.
  • Remove stored password hashes from publicly reachable endpoints or modify the API to exclude sensitive data when responding to share links.

Generated by OpenCVE AI on September 10, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.
Title OpenPanel Unauthenticated Share Lookup Information Disclosure
First Time appeared Openpanel
Openpanel openpanel
Weaknesses CWE-200
CPEs cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:*
Vendors & Products Openpanel
Openpanel openpanel
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openpanel Openpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:55:35.651Z

Reserved: 2026-09-10T11:28:50.296Z

Link: CVE-2026-88893

cve-icon Vulnrichment

Updated: 2026-09-10T14:22:21.323Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:17:18.620

Modified: 2026-09-10T15:17:58.827

Link: CVE-2026-88893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor