---
id: CVE-2026-88891
title: >-
  OpenPanel fails to enforce read-only project access level on 26 of 29 mutating
  procedures, allowing read-level members to modify, delete, and publish project
  data
summary: >-
  OpenPanel fails to enforce read-only project access level on 26 of 29 mutating
  procedures, allowing read-level members to modify, delete, and publish project
  data. Attackers with explicit read-only access can delete reports and
  dashboard…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-269
vendor: Openpanel-dev
product: openpanel
affected:
  - openpanel <= worker
published: '2026-09-10'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:17:26.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88891'
references:
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-f9rx-pxgw-c6rg
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openpanel-read-only-access-level-enforcement-bypass-via-mutations
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-f9rx-pxgw-c6rg
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T14:25:18.502698Z'
epss: 0.00371
epssPercentile: 0.2837
ingestedAt: '2026-09-13T14:47:15.814Z'
---

## Overview

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
