OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries. | |
| Title | OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T11:30:07.432Z
Reserved: 2026-09-04T11:01:47.585Z
Link: CVE-2026-85611
No data.
Status : Received
Published: 2026-09-04T12:17:24.593
Modified: 2026-09-04T12:17:24.593
Link: CVE-2026-85611
No data.
OpenCVE Enrichment
Updated: 2026-09-04T12:45:03Z
Weaknesses