← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 19, 2026 · 12:16via CVEFeed

CVE-2026-93983 - OpenPanel SQL Injection via ClickHouse Property Key Filter

Brief

CVE ID : CVE-2026-93983

Published : Sept. 19, 2026, 12:16 p. m.

  • 8 hours, 40 minutes ago

Description : OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.

Severity: 5.3

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→