CVE-2026-93984
Received Received - Intake

OpenPanel Tracking API Client Secret Verification Bypass

Vulnerability report for CVE-2026-93984, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: VulnCheck

Description

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenPanel tracking API fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

Impact Analysis

Attackers could manipulate revenue metrics by injecting false data, leading to incorrect financial reporting or analytics. Bot detection bypass could skew traffic analysis, affecting decision-making based on user behavior metrics.

Compliance Impact

The vulnerability allows attackers to inject forged revenue metrics and bypass bot detection filters by exploiting the lack of client secret verification. This could lead to inaccurate data reporting, which may impact compliance with regulations requiring accurate financial or operational reporting, such as GDPR (data integrity principles) or HIPAA (audit log integrity). However, the provided context does not specify direct compliance impacts.

Mitigation Strategies

Immediately verify that the OpenPanel tracking API enforces client secret verification before processing revenue events or bot filtering. Ensure all client secrets are cryptographically validated and reject requests with dummy or missing secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93984. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart