MEDIUMVulnerability

CVE-2026-85615

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts and configurations or delete dashboard grid arrangements across tenants.

Properties

severity
MEDIUM
score
6.4
cve_id
CVE-2026-85615
signal_observed_at
2026-09-16T05:25:27+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
published_at
2026-09-04T12:17:25.130
last_modified
2026-09-10T16:17:59.917

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85615 — Ninja Signal Threat Intelligence | Ninja Signal