PatchSiren

OpenLIT CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenLIT CVE published 2026-10-10

CVE-2026-108596

CVE-2026-108596 is an authorization bypass vulnerability in OpenLIT 2.1.0 that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. This issue may impact users who have deployed OpenLIT 2.1.0 and have multiple projects configured. The vulnerability can be exploited by attackers who know a victim project id and database config id, allowing them to [truncated]