CVE-2026-93982
Severity CVSS v4.0:
MEDIUM
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
19/09/2026
Last modified:
02/10/2026
Description
OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
3.30
Severity 3.x
LOW


