---
id: CVE-2026-85611
title: >-
  OpenPanel before 2.3.0 contains a cross-tenant broken object level
  authorization vulnerability in the report.getLayouts and report.resetLayout
  tRPC procedures that fail to scope dashboard queries to the caller's project
summary: >-
  OpenPanel before 2.3.0 contains a cross-tenant broken object level
  authorization vulnerability in the report.getLayouts and report.resetLayout
  tRPC procedures that fail to scope dashboard queries to the caller's project.
  Authenticated at…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-639
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85611'
references:
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-g3xf-pqfp-22v7
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openpanel-before-2.3.0-cross-tenant-bola-via-report-procedures
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-g3xf-pqfp-22v7
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00239
epssPercentile: 0.13317
ingestedAt: '2026-09-08T21:11:12.294Z'
---

## Overview

OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId with a victim organization's guessable dashboardId to read confidential report definitions or permanently delete dashboard layouts across tenant boundaries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
