CVE-2026-85612: OpenPanel before 2.3.0 SSRF via favicon and og endpoints

Published Sep 4, 2026
·
Updated

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.

Affected Software

1 affected component
Openpanel<2.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenPanel to a version that resolves this vulnerability.

    Fixed in 2.3.0
  2. Configuration

    Mitigate the SSRF issue by fixing/strengthening validation for the attacker-supplied url parameter on the unauthenticated /misc/favicon and /misc/og endpoints (OpenPanel before 2.3.0); apply the vendor fix by upgrading to 2.3.0 or later.

    OpenPanel /misc/favicon and /misc/og endpoints url parameter validation = insufficient validation (unspecified exact setting)

Event History

Sep 4, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

OpenPanel versions before 2.3.0 are affected if the /misc/favicon or /misc/og endpoints are reachable by an attacker. The vulnerability is unauthenticated, so no account or prior access is required.

2

What can an attacker access through the vulnerable endpoints?

An attacker can supply a URL that causes the server to fetch arbitrary internal hosts and cloud metadata endpoints. Small responses are returned verbatim, which can enable internal service enumeration and theft of credentials exposed by metadata services.

3

How can I determine whether an instance is vulnerable?

Check whether the deployed OpenPanel version is earlier than 2.3.0 and whether it exposes /misc/favicon or /misc/og endpoints that accept a url parameter. Affected endpoints perform insufficient validation of attacker-supplied URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203