CVE-2026-85614: OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker
Published Sep 4, 2026
·Updated
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal services, localhost, and cloud metadata endpoints, reading internal HTTP response titles, headers, status codes, and SSL certificate information.
Affected Software
1 affected component
OpenPanel API<2.3.0
Event History
Sep 4, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which OpenPanel API versions are affected?
OpenPanel API versions before 2.3.0 are affected.
2
Does an attacker need an account or user interaction to exploit this issue?
No. The affected endpoint can be reached without authentication, and exploitation does not require user interaction.