CVE-2026-93982 MEDIUM

CVE-2026-93982: OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext

Vendor Openpanel-Dev
Product openpanel
Weakness CWE-532 · Sensitive info in logs
Published September 19, 2026
Last update September 19, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics.

Key dates

02Disclosure timeline

September 19, 2026 CVE published

Related vulnerabilities

04Related CVE