Description
OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.
Published: 2026-09-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch
AI Analysis

Impact

The OpenPanel tracking API through version 2.3.0 fails to verify the cryptographic hash of client secrets before authorizing revenue events and bot‑filtering requests. This flaw allows an attacker who knows only the publicly exposed client ID to supply arbitrary dummy secrets, enabling the injection of forged revenue metrics and the bypass of bot detection mechanisms. The resulting unauthorized data can lead to false revenue reporting, financial fraud, and evasion of moderation controls.

Affected Systems

OpenPanel tracking API released by Openpanel-dev, versions up to and including 2.3.0. Any deployment running these versions is impacted; no additional upstream or version numbers are provided in the advisory.

Risk and Exploitability

The CVSS v3 score of 6.9 indicates moderate severity, while the EPSS score of < 1% reflects a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers need only the public client ID, which is typically disclosed, and can therefore construct a malicious request with any dummy secret over the network. Because the secret is unverified before authorizing revenue events or bot‑filtering requests, exploitation is straightforward for a remote attacker with internet access. The potential for fraudulent revenue or bot evasion is significant, especially for services that rely on the API for revenue tracking or moderation, and a lack of alerting for abnormal event patterns could permit rapid exploitation.

Generated by OpenCVE AI on October 2, 2026 at 16:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenPanel to the latest release that includes the fix for client‑secret validation
  • Implement server‑side logic to verify the cryptographic hash of client secrets before authorizing revenue events or bot‑filtering requests
  • Set up monitoring to flag anomalous revenue event submissions or unusual traffic patterns indicative of forged client‑secret usage
  • Enforce stricter client‑secret management policies, such as rotating secrets, using HMAC verification, or limiting API access to trusted IP ranges

Generated by OpenCVE AI on October 2, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters. OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.
Title OpenPanel API Authentication Bypass via Unverified Client Secret OpenPanel API through 2.3.0 Authentication Bypass via Unverified Client Secret
CPEs cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:*

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 16:30:00 +0000


Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.
Title OpenPanel API Authentication Bypass via Unverified Client Secret
First Time appeared Openpanel
Openpanel openpanel
Weaknesses CWE-287
CPEs cpe:2.3:a:openpanel:openpanel:-:*:*:*:*:*:*:*
Vendors & Products Openpanel
Openpanel openpanel
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openpanel Openpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:00:44.275Z

Reserved: 2026-09-19T10:55:49.093Z

Link: CVE-2026-93984

cve-icon Vulnrichment

Updated: 2026-09-22T15:56:27.013Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T12:16:41.723

Modified: 2026-10-02T15:17:12.930

Link: CVE-2026-93984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:15:08Z

Weaknesses