CVE-2026-93984 MEDIUM

CVE-2026-93984: OpenPanel API Authentication Bypass via Unverified Client Secret

Vendor Openpanel-Dev
Product openpanel
Weakness CWE-287 · Improper authentication
Published September 19, 2026
Last update September 19, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

Key dates

02Disclosure timeline

September 19, 2026 CVE published

Related vulnerabilities

04Related CVE