CVE-2026-85613: OpenPanel Unauthenticated XSS via SVG Favicon Proxy

Published Sep 4, 2026
·
Updated

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints.

Affected Software

1 affected component
OpenPanel OpenPanel<2.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenPanel to a version that resolves this vulnerability.

    Fixed in 2.3.0
  2. Compensating control

    Restrict or block unauthenticated access to the favicon proxy endpoint GET /misc/favicon to prevent remote SVG URLs from being rendered via the vulnerable unauthenticated endpoint.

Event History

Sep 4, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

OpenPanel versions before 2.3.0 are affected. The vulnerable endpoint is the unauthenticated GET /misc/favicon endpoint.

2

What does an attacker need to exploit this issue?

An attacker can remotely supply a URL to an attacker-hosted SVG file containing embedded script. Exploitation requires a victim to interact with the malicious content in their browser.

3

What is the impact if exploitation succeeds?

The embedded script executes on the OpenPanel API origin. This can enable same-origin, credentialed requests to authenticated endpoints, with high confidentiality impact and low integrity impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203