VYPR
Medium severity5.3NVD Advisory· Published Sep 19, 2026

CVE-2026-93984

CVE-2026-93984

Description

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.