OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal services, localhost, and cloud metadata endpoints, reading internal HTTP response titles, headers, status codes, and SSL certificate information.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal services, localhost, and cloud metadata endpoints, reading internal HTTP response titles, headers, status codes, and SSL certificate information. | |
| Title | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | |
| First Time appeared |
Openpanel
Openpanel openpanel |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openpanel
Openpanel openpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T11:30:09.411Z
Updated: 2026-09-04T12:40:28.186Z
Reserved: 2026-09-04T11:01:47.585Z
Link: CVE-2026-85614
Updated: 2026-09-04T12:40:22.523Z
Status : Deferred
Published: 2026-09-04T12:17:24.993
Modified: 2026-09-08T20:18:59.270
Link: CVE-2026-85614
No data.