CVE-2026-93983: OpenPanel SQL Injection via ClickHouse Property Key Filter

Published Sep 19, 2026
·
Updated

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.

Affected Software

1 affected component
OpenPanel OpenPanel>undefined

Event History

Sep 19, 2026
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs to be an authenticated OpenPanel user and able to supply crafted property-key filter names. The issue is remotely reachable and does not require user interaction.

2

What is the practical impact?

Crafted boolean SQL terms can bypass project isolation, allowing an authenticated user to access metrics belonging to other projects. The provided impact information indicates confidentiality exposure, with no stated integrity or availability impact.

3

Are default deployments affected?

The provided information does not identify a configuration prerequisite or mitigation setting. Deployments running OpenPanel through commit bad75bdd should be treated as potentially affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203