SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88893

HIGH · CVSS 7.5 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

OpenPanel's share lookup procedures are vulnerable due to inadequate access control validation, allowing unauthenticated attackers to access sensitive information such as argon2id password hashes and detailed report configurations. This flaw poses a significant risk of offline password cracking and potential business intelligence theft. Organizations using OpenPanel should prioritize addressing this vulnerability to safeguard their data and prevent unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88893
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.