Loading market data...
← Back to CVE feed

CVE-2026-93983

MEDIUM CVSS 5.0 View on NVD ↗

Description

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Published: Sep 19, 2026 12:16 UTC Modified: Sep 19, 2026 12:16 UTC