medium · CVSS v3 5.3 · CVSS v4 6.9
CVE-2026-93984
The OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to cryptographically verify client secrets prior to
Overview
The OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to cryptographically verify client secrets prior to authorizing revenue events and bot filtering. Attackers possessing only a public client ID can supply arbitrary dummy values to inject forged revenue metrics and bypass bot detection mechanisms. This integrity failure compromises analytics reliability and may skew business intelligence data.
Description
OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.
Impact
Integrity impact is moderate as unauthorized actors can manipulate revenue metrics and bypass bot filtering controls, leading to corrupted analytics data. Confidentiality and availability remain unaffected. Website administrators and businesses relying on accurate traffic and revenue reporting are impacted.
Remediation
Apply the latest vendor patches or updates beyond commit bad75bddc74d12d36cfb843f4531d3b830a8d994. Ensure the tracking API correctly validates cryptographic client secret hashes before processing revenue and bot filtering events. Monitor analytics platforms for sudden, unexplained anomalies in revenue metrics or traffic volumes.
Risk context
The vulnerability holds a medium severity with a CVSS v3 score of 5.3 and a CVSS v4 score of 6.9, indicating moderate risk. No EPSS data is currently available, suggesting limited active exploitation metrics in the wild. Defenders should prioritize remediation as part of standard update cycles to protect analytics integrity.
Affected products
- OpenPanel OpenPanel
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- —