{"advisories":[{"id":"GHSA-cjgj-2fwf-4c2w","source":"ghsa","title":"Perses's project query parameter authorization bypass exposes cross-project resources","url":"https://github.com/advisories/GHSA-cjgj-2fwf-4c2w"}],"cve":"CVE-2026-63458","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[0,0.54.0-beta.3)"}}],"enrichment":{"confidence":100.0,"confidence_source":"cna","scores":[{"score":100.0,"source":"cna"}]},"original":{"product":"perses","source":"cna","vendor":"perses"},"product":"perses","vendor":"perses"}],"created":"2026-09-19T12:00:08.779339+00:00","updated":"2026-09-21T10:04:23.409209+00:00","vendors":["perses","perses$PRODUCT$perses"]},"epss":{"score":0.00303},"mitre":{"cpes":[],"created":"2026-09-18T17:32:54.847000+00:00","description":"Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/63xxx/CVE-2026-63458.json","references":["https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540","https://github.com/perses/perses/releases/tag/v0.54.0-beta.3","https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w"],"title":"Perses project query parameter authorization bypass exposes cross-project resources","updated":"2026-09-18T19:50:33.901000+00:00","vendors":[],"weaknesses":["CWE-639"]},"nvd":{"cpes":[],"created":"2026-09-18T18:17:10.643000+00:00","description":"Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-63458.json","references":["https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540","https://github.com/perses/perses/releases/tag/v0.54.0-beta.3","https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w"],"title":null,"updated":"2026-09-23T18:12:04.247000+00:00","vendors":[],"weaknesses":["CWE-639"]},"opencve":{"changes":[{"created":"2026-09-18T21:30:00+00:00","data":[{"details":{"new":"Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.","old":null},"type":"description"},{"details":{"new":"Perses project query parameter authorization bypass exposes cross-project resources","old":null},"type":"title"},{"details":{"added":["CWE-639"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540","https://github.com/perses/perses/releases/tag/v0.54.0-beta.3","https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"a19c8a21-9d0e-4cc9-86dd-227444b78824"},{"created":"2026-09-21T10:45:00+00:00","data":[{"details":["perses","perses$PRODUCT$perses"],"type":"first_time"},{"details":{"added":["perses","perses$PRODUCT$perses"],"removed":[]},"type":"vendors"}],"id":"cec13f64-837c-4acd-a402-927591c46850"},{"created":"2026-09-23T00:15:00+00:00","data":[{"details":{"added":["https://nvd.nist.gov/vuln/detail/CVE-2026-63458","https://www.cve.org/CVERecord?id=CVE-2026-63458"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}},"removed":{},"updated":{"threat_severity":{"new":"Moderate","old":null}}},"type":"metrics"}],"id":"6ad6170a-5ea7-4dcb-9389-7be8e1aafbc8"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-18T17:32:54+00:00","provider":"redhat"},"description":{"data":"Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},"provider":"redhat"},"cvssV4_0":{"data":{"score":7.1,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.00303},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":"Moderate","provider":"redhat"}},"references":{"data":["https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540","https://github.com/perses/perses/releases/tag/v0.54.0-beta.3","https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w","https://nvd.nist.gov/vuln/detail/CVE-2026-63458","https://www.cve.org/CVERecord?id=CVE-2026-63458"],"providers":["mitre","nvd","redhat"]},"title":{"data":"Perses project query parameter authorization bypass exposes cross-project resources","provider":"mitre"},"updated":{"data":"2026-09-21T10:04:23.409209+00:00","provider":"enrichment"},"vendors":{"data":["perses","perses$PRODUCT$perses"],"providers":["enrichment"]},"weaknesses":{"data":["CWE-639"],"providers":["mitre","nvd","redhat"]}},"redhat":{"cpes":[],"created":"2026-09-18T17:32:54+00:00","description":"Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},"threat_severity":"Moderate"},"redhat_repo_path":"2026/CVE-2026-63458.json","references":["https://github.com/perses/perses/commit/8015fb340bdc625953e73a7a688be5b939159540","https://github.com/perses/perses/releases/tag/v0.54.0-beta.3","https://github.com/perses/perses/security/advisories/GHSA-cjgj-2fwf-4c2w","https://nvd.nist.gov/vuln/detail/CVE-2026-63458","https://www.cve.org/CVERecord?id=CVE-2026-63458"],"title":"github.com/perses/perses: Perses: Information disclosure via query parameter authorization bypass","updated":"2026-09-18T17:32:54+00:00","vendors":[],"weaknesses":["CWE-639"]},"vulnrichment":{"cpes":[],"created":"2026-09-18T17:32:54.847000+00:00","description":"Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on project-scoped list endpoints, including /api/v1/projects/{project}/dashboards and /api/v1/datasources. The request-controlled project value is used to select dashboards, datasources, and variables without enforcing the caller's authorization for that selected project, which breaks project-level tenant isolation and exposes complete resource specifications belonging to other projects. This issue is fixed in version 0.54.0-beta.3.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Perses project query parameter authorization bypass exposes cross-project resources","updated":"2026-09-18T19:50:29.857000+00:00","vendors":[],"vulnrichment_repo_path":"2026/63xxx/CVE-2026-63458.json","weaknesses":[]}}