Junglewise Threat Intelligence

CVE-2026-88892: OpenPanel SSRF in data importer via unguarded fetch

CVE-2026-88892 · Severity: medium · CVSS 5 · Published 2026-09-10

Technologies: OpenPanel. Vendors: OpenPanel.

Executive brief

OpenPanel is an analytics platform that imports data from external sources. An authenticated organization member can trick the server into making requests to internal hosts, ports, and cloud metadata services by supplying a malicious URL to the data importer. The attacker can read HTTP status codes and response details back, effectively using the platform as a scanner for internal network infrastructure, and could potentially ingest sensitive internal data into their analytics views.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) in the data importer component (packages/importer/src/providers/umami.ts). The parseRemoteFile function calls fetch() directly on a user-supplied fileUrl parameter with only basic URL format validation (z.string().url()), bypassing the application's existing SSRF guard (safe-fetch.ts) that validates addresses and blocks non-publicly-routable ranges. An authenticated organization member—including default members with no explicit project access—can exploit this because getProjectAccess returns a boolean true rather than an access level object, causing the intended read-level access check to be skipped. The attacker can make the server connect to loopback addresses (127.0.0.1), private networks (10.0.0.0/8, 192.168.0.0/16), and cloud metadata endpoints (169.254.169.254). HTTP error responses are reflected in Import.errorMessage and returned to the attacker, providing a scanning oracle for internal hosts and paths; if responses parse as Umami CSV, data is ingested into the attacker's analytics views. No patched version is available at time of publication.

Affected products

  • OpenPanel OpenPanel all versions

Timeline

  • 2026-09-10: disclosed
  • 2026-08-26: advisory

References

Related threats