OpenPanel's failure to enforce read-only project access levels on 26 of 29 mutating procedures allows read-level members to modify, delete, and publish project data. This vulnerability, tracked as CVE-2026-88891, has a CVSS score of 7.2 and is considered high severity. The issue arises from missing access level validation in mutation resolvers, enabling unauthorized modifications and data loss. Defenders [truncated]
An authenticated user could pair a projectId from their own organization with a dashboardId belonging to another organization and receive every report in that dashboard due to insufficient verification in the report.list procedure. This issue arises from the report.list procedure in Openpanel's packages/trpc/src/routers/report.ts not properly verifying that the supplied dashboardId belonged to the project [truncated]
CVE-2026-77768 is a high-severity vulnerability in Openpanel, an open-source project management platform. The vulnerability exists in the report.get procedure, which allows any authenticated user to read the full configuration of any saved report on the instance by supplying its identifier. This is possible because the enforceAccess middleware does not evaluate membership when the input only contains a re [truncated]