Unauthenticated Server-Side Request Forgery Vulnerability in Openpanel
CVE-2026-85609

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85609?

Openpanel versions prior to 2.3.0 exhibit a critical security flaw within the GET /tools/site-checker endpoint, allowing unauthenticated attackers to exploit the system. By supplying a malicious URL in the query parameters, the vulnerability permits the server to execute unauthorized HTTP requests to arbitrary locations without validating the SSRF/IP. This could lead to an attacker accessing cloud instance metadata, probing internal services, and scanning network ports. Such exploits can result in the leakage of sensitive internal IP addresses and information, making it imperative for users to update to the latest version.

Affected Version(s)

openpanel 0 < 2.3.0

openpanel 2.3.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.