Server-Side Request Forgery in OpenPanel Analytics Platform
CVE-2026-88892
5.3MEDIUM
What is CVE-2026-88892?
The OpenPanel Analytics Platform suffers from a vulnerability where the data importer fetches a caller-supplied URL without proper validation, bypassing the existing SSRF guard. This flaw allows authenticated users to make the server connect to any reachable address. An attacker could exploit this vulnerability to gather internal host information, leading to a potential data breach as internal responses could be parsed and ingested by the attacker's analytics view. The flaws are present in all versions of the product, necessitating immediate attention to mitigate risks.
Affected Version(s)
openpanel 0
