Security Advisory

CVE-2026-88890

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-10 13:05:38
Last updated 2026-09-11 19:29:58
Assigner VulnCheck
CVSS score 8.5
State PUBLISHED

Description

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.