{"id":"CVE-2026-63458","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63458","summary":"Perses's project query parameter authorization bypass exposes cross-project resources","details":"### Impact\n_What kind of vulnerability is it?_\n\nAn authenticated user who is only a viewer on project team-a requests GET /api/v1/projects/team-a/dashboards?project=finance-secret (or simply GET /api/v1/datasources?project=finance-secret) and receives the full list of the finance-secret project's dashboards and datasource specifications, despite having no role on that project. This defeats Perses' project-level tenant isolation for all project-scoped read resources.\n\n_Who is impacted?_\n\nAny authenticated user reads every project's dashboards, datasources, variables across tenants.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\n### Workarounds\nNone","published":"2026-09-18T17:39:31Z","modified":"2026-09-18T17:45:05.850557114Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/perses/perses","fixedVersion":"0.54.0-beta.3"}],"fix":{"url":"https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540","label":"perses/perses@8015fb3"},"references":[{"type":"WEB","url":"https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w"},{"type":"WEB","url":"https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540"},{"type":"PACKAGE","url":"https://github.com/perses/perses"},{"type":"WEB","url":"https://github.com/perses/perses/releases/tag/v0.54.0-beta.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-18T17:45:05.850557114Z"}}