Junglewise Threat Intelligence

CVE-2026-85612: OpenPanel server-side request forgery in favicon and OG endpoints

CVE-2026-85612 · Severity: high · CVSS 7.5 · Published 2026-09-04

Technologies: OpenPanel. Vendors: OpenPanel.

Executive brief

OpenPanel is a hosting control panel API that provides web application management. The /misc/favicon and /misc/og endpoints allow unauthenticated attackers to make arbitrary HTTP requests to internal servers and cloud metadata services, potentially exposing sensitive credentials and internal service information. An attacker can retrieve internal resources and cloud IAM credentials without authentication.

Technical details

This is an unauthenticated server-side request forgery (SSRF) vulnerability in OpenPanel before 2.3.0. The /misc/favicon and /misc/og endpoints accept a user-supplied URL parameter with insufficient validation—only checking for http/https protocols but allowing access to private IP ranges and internal hostnames. The fetchImage() function follows redirects without filtering, allowing bypass of the image-extension check. Small responses (under 5 KB for /favicon, under 10 KB for /og) are returned verbatim to the attacker, enabling credential theft from cloud metadata endpoints and enumeration of internal services. No authentication is required; the endpoints are mounted without auth preHandlers.

Affected products

  • OpenPanel OpenPanel before 2.3.0

Timeline

  • 2026-08-20: disclosed: Security advisory published by OpenPanel
  • 2026-09-04: patched: Fixed in version 2.3.0

References

Related threats