CVE-2026-77769 | Openpanel-dev Openpanel enforceAccess middleware report.ts report.list projectId/dashboardId authorization

SecurityVulns

A vulnerability, which was classified as problematic, was found in Openpanel-dev Openpanel. This affects the function report.list of the file packages/trpc/src/routers/report.ts of the component enforceAccess middleware. Such manipulation of the argument projectId/dashboardId leads to missing authorization.

This vulnerability is listed as CVE-2026-77769. The attack may be performed from remote. There is no available exploit.

Applying a patch is advised to resolve this issue.VulDB Recent EntriesRead More