CyberRota Analysis
AI-GeneratedOpenPanel has a critical vulnerability that allows users with read-only access to manipulate project data through 26 out of 29 mutating procedures. This flaw enables unauthorized actions such as deleting reports and dashboards, scheduling project deletions, publishing private analytics publicly, and altering alerting rules. Organizations using OpenPanel should prioritize addressing this issue to prevent potential data loss and unauthorized data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.