OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration. | |
| Title | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T11:30:08.089Z
Reserved: 2026-09-04T11:01:47.585Z
Link: CVE-2026-85612
No data.
Status : Received
Published: 2026-09-04T12:17:24.727
Modified: 2026-09-04T12:17:24.727
Link: CVE-2026-85612
No data.
OpenCVE Enrichment
Updated: 2026-09-04T13:30:05Z
Weaknesses