CVE-2026-85610 - OpenPanel before 2.3.0 Remote Code Execution via chart formulas

CVE Advisories
Post Reply
Starburst-David
Posts: 286
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-85610 - OpenPanel before 2.3.0 Remote Code Execution via chart formulas

Post by Starburst-David »

CVE ID :CVE-2026-85610
Published : Sept. 4, 2026
Description :OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered constructor to load Node.js built-ins and execute operating system commands with the privileges of the API process, bypassing organization authorization boundaries.
Severity: 8.8 | HIGH

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-85610
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”