Junglewise Threat Intelligence

CVE-2026-85614: OpenPanel unauthenticated SSRF in site-checker

CVE-2026-85614 · Severity: high · CVSS 8.6 · Published 2026-09-04

Technologies: OpenPanel. Vendors: OpenPanel.

Executive brief

OpenPanel is a self-hosted control panel for managing web infrastructure. The site-checker endpoint allows any unauthenticated attacker to make the OpenPanel server fetch arbitrary URLs, including internal services and cloud metadata endpoints. An attacker can read sensitive information like page titles, HTTP headers, SSL certificates, and internal IP addresses—effectively scanning the internal network without authentication.

Technical details

The vulnerability is an unauthenticated server-side request forgery (SSRF) in the GET /tools/site-checker endpoint. The endpoint accepts a fully client-controlled URL parameter with only basic URL parsing validation, and lacks private IP filtering, DNS-rebinding protection, and per-hop validation on redirects. An attacker can make the server issue HTTP(S) requests to localhost, internal services, and cloud metadata endpoints (169.254.169.254), with response data (page titles, headers, status codes, SSL issuer/expiry, resolved internal IPs) reflected back in JSON. The handler follows up to 10 redirects manually without re-validating the destination IP, enabling DNS-rebinding attacks. OpenPanel 2.3.0 and later patch this issue by adding private IP validation and resolving then pinning IPs before connection.

Affected products

  • OpenPanel OpenPanel before 2.3.0

Timeline

  • 2026-08-20: disclosed: Security advisory published on GitHub (GHSA-gqcr-xgfj-pq29)
  • 2026-09-04: patched: OpenPanel 2.3.0 released with patch

References

Related threats