Description
OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Project Metrics
Action: Patch
AI Analysis

Impact

OpenPanel through version 2.3.0 does not escape property keys in ClickHouse SQL queries, which allows an authenticated user to inject boolean SQL terms. Attackers can supply crafted filter names to bypass the standard project isolation logic, granting them read access to metrics from projects they should not normally be able to view. This flaw is a classic SQL injection vulnerability (CWE‑89) that permits unauthorized access to project‑specific data.

Affected Systems

The affected product is Openpanel-dev's OpenPanel application. Versions up to and including 2.3.0 are affected, and no specific version range beyond that is identified in the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is < 1%, implying a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not presently known to be actively exploited. The attack vector requires an authenticated user with access to the web interface that accepts property key filters. Once authenticated, the attacker can craft a filter name that injects boolean SQL, thereby retrieving metrics from other projects. This promotes unauthorized data disclosure with limited operational impact beyond visibility.

Generated by OpenCVE AI on October 2, 2026 at 16:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch that correctly escapes property keys in ClickHouse queries.
  • Configure the ClickHouse service to disallow or sanitize property key inputs, ensuring that only allowed characters are accepted.
  • Audit activity logs for unexpected query patterns and monitor for unusual metric retrievals from the application.

Generated by OpenCVE AI on October 2, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects. OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Title OpenPanel SQL Injection via ClickHouse Property Key Filter OpenPanel through 2.3.0 SQL Injection via ClickHouse Property Key Filter
CPEs cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:*

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Title OpenPanel SQL Injection via ClickHouse Property Key Filter
First Time appeared Openpanel
Openpanel openpanel
Weaknesses CWE-89
CPEs cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:*
Vendors & Products Openpanel
Openpanel openpanel
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Openpanel Openpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:00:43.185Z

Reserved: 2026-09-19T10:55:49.093Z

Link: CVE-2026-93983

cve-icon Vulnrichment

Updated: 2026-09-21T14:48:59.330Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T12:16:41.493

Modified: 2026-10-02T15:17:12.807

Link: CVE-2026-93983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:15:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')