Beveiligingsadvies

CVE-2026-85614

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 11:30:09
Laatst bijgewerkt 2026-09-04 12:40:28
Toegewezen door VulnCheck
CVSS-score 9.2
Status PUBLISHED

Beschrijving

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel server issue requests to internal services, localhost, and cloud metadata endpoints, reading internal HTTP response titles, headers, status codes, and SSL certificate information.