CVE-2026-85611 | Openpanel-dev OpenPanel up to 2.2.x tRPC Procedures report.getLayouts/report.resetLayout projectId/dashboardId authorization
A vulnerability was found in Openpanel-dev OpenPanel up to 2.2.x. It has been classified as critical. The affected element is the function report.getLayouts/report.resetLayout of the component tRPC Procedures. This manipulation of the argument projectId/dashboardId causes authorization bypass.
This vulnerability is tracked as CVE-2026-85611. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More