CVE-2026-88893
—Broken Access Control in OpenPanel Share Links Exposes Password Hashes
CVE-2026-88893 is an information disclosure flaw in OpenPanel's share lookup procedures, which fail to enforce access controls before returning protected data. An unauthenticated attacker who obtains or knows a share link can call the share lookup endpoint and receive argon2id password hashes as well as full report configurations, including event names, filters, and breakdown dimensions. With the exposed argon2id hashes, an attacker can attempt offline password cracking, and the leaked report definitions disclose business intelligence such as tracked events and how dashboards are segmented. Any OpenPanel deployment with dashboard or report sharing enabled is affected, since no authentication or privilege is required beyond access to a share link. As of this analysis there is no entry in CISA's KEV catalog and no public proof-of-concept, so exploitation is not confirmed.
What to do: Monitor the vendor for a patched release and upgrade as soon as a fixed version is announced, since the disclosure does not specify affected version ranges. Until patched, audit or disable public share links, and check access logs for unauthenticated requests to share lookup endpoints. Rotate any dashboard/user passwords whose argon2id hashes may have been exposed through share links, as they could be cracked offline.
| OpenPanel | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.
- Weakness
- CWE-200
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.