CVE-2026-88890

OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.

  • Published Sep 10, 2026
  • CVSS 8.4 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-88890 at the National Vulnerability Database