CVE-2026-85615 | Openpanel-dev Openpanel up to 2.2.x tRPC Procedures report.getLayouts/report.resetLayout dashboardId/projectId resource injection
A vulnerability was found in Openpanel-dev Openpanel up to 2.2.x. It has been declared as critical. The impacted element is the function report.getLayouts/report.resetLayout of the component tRPC Procedures. Such manipulation of the argument dashboardId/projectId leads to improper control of resource identifiers.
This vulnerability is listed as CVE-2026-85615. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More