← Back to overview

OpenPanel versions before 2.3.0 are affected by an unauthenticated server-side request forgery (SSRF) vulnerability. The vulnerability exists in the /misc/favicon and /misc/og endpoints, which accept an attacker-supplied url parameter without sufficient validation. Attackers can exploit this flaw to force the API to fetch arbitrary internal hosts and cloud metadata endpoints. Because small responses are returned verbatim to the attacker, this enables credential theft and internal service enumeration. No authentication is required to exploit this vulnerability, significantly raising its risk. Cloud environments are particularly at risk due to exposure of metadata services such as AWS IMDSv1. The issue is resolved in OpenPanel version 2.3.0. Users are strongly advised to upgrade immediately. References include the NVD entry, a GitHub security advisory, and a VulnCheck advisory.

Affected products

  • OpenPanel

Related CVE's

  • CVE-2026-85612

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities