PatchSiren cyber security CVE debrief
CVE-2026-77769 Openpanel-dev CVE debrief
An authenticated user could pair a projectId from their own organization with a dashboardId belonging to another organization and receive every report in that dashboard due to insufficient verification in the report.list procedure. This issue arises from the report.list procedure in Openpanel's packages/trpc/src/routers/report.ts not properly verifying that the supplied dashboardId belonged to the projectId. As a result, an authenticated user could access reports from another organization, leading to potential unauthorized data disclosure.
- Vendor
- Openpanel-dev
- Product
- openpanel
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-23
Who should care
Defenders responsible for Openpanel installations, particularly those with multi-organization setups, should assess exposure and prioritize remediation to prevent unauthorized report access.
Why it matters
CVE-2026-77769 allows authenticated users to access reports from other organizations due to insufficient verification in the report.list procedure, posing a risk of unauthorized data disclosure.
- Potential unauthorized access to sensitive reports across organizations
- Increased risk of data breaches or information disclosure
- Need for verification of dashboardId ownership in report.list procedure
- Priority for remediation to prevent exploitation
Technical summary
The report.list procedure in Openpanel's packages/trpc/src/routers/report.ts did not properly verify that the supplied dashboardId belonged to the projectId, allowing an authenticated user to access reports from another organization. This vulnerability highlights the need for proper verification of dashboardId ownership in the report.list procedure to prevent unauthorized report access across organizations. The issue can be resolved by implementing proper dashboardId verification in the report.list procedure, restricting access to authorized users and projects, and reviewing compensating controls for exposed systems.
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability in Openpanel installations to prevent unauthorized report access across organizations.
Recommended defensive actions
- Verify Openpanel installations for vulnerability to CVE-2026-77769
- Restrict report.list procedure access to authorized users and projects
- Implement proper dashboardId verification in report.list procedure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source references indicate that the report.list procedure did not properly verify dashboardId ownership, allowing cross-organization report access. The issue is caused by the lack of verification between projectId and dashboardId in the report.list procedure, which allows an authenticated user to access reports from another organization. This vulnerability highlights the need for proper verification of dashboardId ownership in the report.list procedure to prevent unauthorized report access.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77769 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77769
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77769 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77769
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Openpanel-dev/openpanel
-
Source reference
Unverified legacy reference
URL: https://github.com/Openpanel-dev/openpanel/blob/e8a0602cda5a4d4b463f11d298a1b078c446bf33/packages/trpc/src/routers/report.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/Openpanel-dev/openpanel/commit/0a51b6805eed0b3da8376175acd5fa3d26819cb6
-
Source reference
Unverified legacy reference
URL: https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-3q95-vc6f-vc9v
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openpanel-report-list-queries-reports-by-an-unverified-dashboardid-crossing-organization-boundaries
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.