OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-63458: Perses's project query parameter authorization bypass exposes cross-project resources

GitHub Advisories · officialPublished Sep 18, 2026Risk 37/100

### Impact _What kind of vulnerability is it?_ An authenticated user who is only a viewer on project team-a requests GET /api/v1/projects/team-a/dashboards?project=finance-secret (or simply GET /api/v1/datasources?project=finance-secret) and receives the full list of the finance-secret project's dashboards and datasource specifications, despite having no role on that project. This defeats Perses' project-level tenant isolation for all project-scoped read resources. _Who is impacted?_ Any authenticated user reads every project's dashboards, datasources, variables across tenants. ### Patches _Has the problem been patched? What versions should users upgrade to?_ ### Workarounds None

Upgrade affected packages to a patched version: github.com/perses/perses 0.54.0-beta.3.

Vendor
Not specified
Product
github.com/perses/perses
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source