SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88891

HIGH · CVSS 8.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

OpenPanel has a critical vulnerability that allows users with read-only access to manipulate project data through 26 out of 29 mutating procedures. This flaw enables unauthorized actions such as deleting reports and dashboards, scheduling project deletions, publishing private analytics publicly, and altering alerting rules. Organizations using OpenPanel should prioritize addressing this issue to prevent potential data loss and unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88891
Severity
HIGH
CVSS
8.3
EPSS
0.25%

Original NVD Description

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.