Beveiligingsadvies

CVE-2026-88890

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-10 13:05:38
Laatst bijgewerkt 2026-09-11 19:29:58
Toegewezen door VulnCheck
CVSS-score 8.5
Status PUBLISHED

Beschrijving

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.