CVE-2026-93983 - OpenPanel SQL Injection via ClickHouse Property Key Filter
Posted: Sun Sep 20, 2026 9:24 am
CVE ID :CVE-2026-93983
Published : Sept. 19, 2026
Description :OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Severity: 5.3 | MEDIUM
More Information:
https://cvefeed.io/vuln/detail/CVE-2026-93983
Published : Sept. 19, 2026
Description :OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Severity: 5.3 | MEDIUM
More Information:
https://cvefeed.io/vuln/detail/CVE-2026-93983