CVE-2026-85612 Details
Description
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.
A server-side request forgery (SSRF) vulnerability has been identified in OpenPanel versions prior to 2.3.0. The vulnerability exists in the '/misc/favicon' and '/misc/og' API endpoints, which accept an attacker-supplied 'url' parameter with inadequate validation. This flaw allows unauthenticated attackers to manipulate the API into fetching data from arbitrary internal hosts and cloud metadata endpoints. The returned small responses can be exploited to steal credentials and enumerate internal services.
Users are advised to update OpenPanel to version 2.3.0 or later, and to implement additional validation on the 'url' parameter to prevent requests to internal or private network addresses.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-2hff-m67f-2w2w | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/openpanel-before-2.3.0-ssrf-via-favicon-and-og-endpoints | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenPanel | >= 0, < 2.3.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion