Home

Description

OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without knowledge of the victim account's password.

PUBLISHED Reserved 2026-02-19 | Published 2026-02-19 | Updated 2026-02-24 | Assigner PRJBLK




CRITICAL: 10.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-287 Improper Authentication

Product status

Default status
unaffected

Any version
affected

References

github.com/...ommit/52f865a4fba763594453068acf8fa9e3fc38d663

github.com/OpenGamePanel/OGP-Website/pull/644

projectblack.io/blog/vibe-hacking-open-game-panel-rce/

cve.org (CVE-2025-15586)

nvd.nist.gov (CVE-2025-15586)

Download JSON