{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/openpanel/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openpanel:openpanel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85609"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Openpanel (\u003c 2.3.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","reconnaissance","remote-code-execution","injection","openpanel"],"_cs_type":"advisory","_cs_vendors":["Openpanel"],"content_html":"\u003cp\u003eOpenpanel versions prior to 2.3.0 contain a critical server-side request forgery (SSRF) vulnerability identified as CVE-2026-85609. The flaw exists in the GET /tools/site-checker endpoint, located in apps/api/src/controllers/tools.controller.ts, which fails to validate user-supplied URL inputs. An unauthenticated attacker can exploit this endpoint by providing a malicious URL parameter to the fetchWithRedirects function.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows attackers to perform unauthorized HTTP requests from the server context, enabling them to probe internal services, scan local network ports, and access cloud instance metadata services (such as AWS/GCP/Azure metadata endpoints). Furthermore, the application returns response details, including status codes, page sizes, and HTML metadata, which can be leveraged for network reconnaissance. The vulnerability also supports leaking internal IP address information to third-party endpoints via the getIPInfo function. Defenders should prioritize patching all Openpanel instances to version 2.3.0 or later to remediate this vector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized visibility into internal network infrastructure, potentially leading to information disclosure of sensitive internal configurations, cloud environment secrets, or local service status. This exposure could serve as a precursor to further exploitation of internal services that were not intended to be internet-facing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure vulnerable Openpanel installations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all Openpanel instances to version 2.3.0 or later to address CVE-2026-85609.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the server hosting Openpanel to restrict network requests to authorized external domains only, preventing access to internal network segments or cloud metadata services.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for repeated requests to /tools/site-checker containing suspicious query parameters, such as internal IP addresses (169.254.169.254, 10.x.x.x, 172.16-31.x.x, 192.168.x.x) or common internal service ports.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T13:26:29Z","date_published":"2026-09-04T13:26:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openpanel-ssrf/","summary":"Openpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.","title":"Unauthenticated SSRF in Openpanel Site Checker","url":"https://feed.craftedsignal.io/briefs/2026-09-openpanel-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Openpanel","version":"https://jsonfeed.org/version/1.1"}