CVE-2026-93984
Deferred Deferred - Pending Action

BaseFortify

Vulnerability report for CVE-2026-93984, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-10-02
Generated
2026-10-10
AI Q&A
2026-09-20
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Openpanel-dev openpanel 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenPanel tracking API fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

Detection Guidance

This vulnerability involves the OpenPanel tracking API failing to verify client secrets before authorizing events. To detect it, monitor API requests for missing or weak secret validation. Check logs for requests with dummy secrets or unauthorized revenue metric injections. Use network monitoring tools to inspect API traffic for suspicious patterns like repeated requests with invalid secrets.

Impact Analysis

Attackers could manipulate revenue metrics by injecting false data, leading to incorrect financial reporting or analytics. Bot detection bypass could skew traffic analysis, affecting decision-making based on user behavior metrics.

Compliance Impact

The vulnerability allows attackers to inject forged revenue metrics and bypass bot detection filters by exploiting the lack of client secret verification. This could lead to inaccurate data reporting, which may impact compliance with regulations requiring accurate financial or operational reporting, such as GDPR (data integrity principles) or HIPAA (audit log integrity). However, the provided context does not specify direct compliance impacts.

Mitigation Strategies

Immediately verify that the OpenPanel tracking API enforces client secret verification before processing revenue events or bot filtering. Ensure all client secrets are cryptographically validated and reject requests with dummy or missing secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93984. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart