HIGH 8.4 NVD
CVE-2026-88890
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifi
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
References
- https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-hwf2-2v2h-7892
- https://www.vulncheck.com/advisories/openpanel-sql-injection-via-unvalidated-profile-filte
This high severity vulnerability with a CVSS score of 8.4 was published on 2026-09-10 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.