CVE-2026-93984

Summary

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

Affected Software

VendorProductVersion RangeStatus
Openpanel-devopenpanel0 <= bad75bddc74d12d36cfb843f4531d3b830a8d994affected

Weaknesses

  • CWE-287: Improper Authentication

References