---
id: CVE-2026-85612
title: >-
  OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery
  vulnerability in the /misc/favicon and /misc/og endpoints that accept an
  attacker-supplied url parameter with insufficient validation
summary: >-
  OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery
  vulnerability in the /misc/favicon and /misc/og endpoints that accept an
  attacker-supplied url parameter with insufficient validation. Attackers can
  force the…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: Openpanel-dev
product: openpanel
affected:
  - openpanel < 2.3.0
published: '2026-09-04'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:16:58.547'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85612'
references:
  - url: >-
      https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-2hff-m67f-2w2w
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openpanel-before-2.3.0-ssrf-via-favicon-and-og-endpoints
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00241
epssPercentile: 0.15578
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/hotplugin0x01/CVE-2026-85612'
  checkedAt: '2026-09-24T07:53:21.474Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T19:19:37.460875Z'
ingestedAt: '2026-09-08T21:11:12.294Z'
---

## Overview

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
