---
id: CVE-2026-85615
title: >-
  Openpanel before 2.3.0 contains an insecure direct object reference
  vulnerability in the report.getLayouts and report.resetLayout tRPC procedures
  that fail to bind dashboardId to the authorized projectId
summary: >-
  Openpanel before 2.3.0 contains an insecure direct object reference
  vulnerability in the report.getLayouts and report.resetLayout tRPC procedures
  that fail to bind dashboardId to the authorized projectId. Authenticated
  attackers can supp…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-639
vendor: Openpanel-dev
product: openpanel
affected:
  - openpanel < 2.3.0
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T16:17:59.917'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85615'
references:
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-5cpv-vqvr-7mrh
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openpanel-before-2.3.0-cross-tenant-idor-via-report-getlayouts
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T14:19:23.261698Z'
epss: 0.00239
epssPercentile: 0.13317
ingestedAt: '2026-09-08T21:11:12.294Z'
---

## Overview

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts and configurations or delete dashboard grid arrangements across tenants.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
