CVE-2026-85610 affects OpenPanel versions before 2.3.0, where chart formula expressions are not properly validated. Authenticated project members with only read access can exploit this flaw by recovering the native JavaScript Function constructor through mathjs matrix objects. Once recovered, attackers can load Node.js built-in modules and execute arbitrary operating system commands. The exploit runs with the privileges of the API process, potentially granting significant system access. This bypass circumvents organization authorization boundaries, escalating a low-privilege user to code execution. The vulnerability is classified as a remote code execution (RCE) issue. A fix is available in OpenPanel 2.3.0. Security advisories have been published on GitHub and VulnCheck. Organizations using OpenPanel should upgrade immediately to mitigate risk.