Skip to main content
EPSS 0.3%top 81%

In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of… (CVE-2026-88892)

0
Medium
Published: 09/10/2026 (09/10/2026, 15:33:19 UTC)
Source: GCVE Database

Description

OpenPanel analytics platform contains a server-side request forgery (SSRF) vulnerability in its data importer component. The importer fetches a caller-supplied URL using a plain fetch method without applying the existing SSRF guard. Authenticated organization members can cause the server to connect to arbitrary internal or external addresses. The HTTP response status and text are stored and returned to the user, enabling internal network scanning. Additionally, if the internal response is in a specific CSV format, it can be ingested as analytics events visible to the attacker. No patched version is available at the time of publication.

CVSS v3.1

Score 5.0medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 17:53:43 UTC

Technical Analysis

CVE-2026-88892 affects all versions of OpenPanel. The data importer fetches URLs supplied by authenticated users using a plain fetch call instead of the project's SSRF protection utility. The URL parameter is only validated as a syntactically valid URL, allowing requests to internal IP addresses such as 127.0.0.1 or 169.254.169.254. An authenticated organization member, including those with minimal access, can exploit this to make the server perform HTTP requests to arbitrary internal or external endpoints. The server's HTTP response status and status text are saved and returned to the user, providing a feedback channel for internal network scanning. If the response is formatted as Umami CSV, it is ingested as analytics events, exposing internal data to the attacker. There is no patch or fix available at the time of disclosure.

Potential Impact

An authenticated user can exploit this SSRF vulnerability to scan internal network hosts, ports, and paths by causing the server to fetch arbitrary URLs. This can lead to information disclosure about internal infrastructure. Additionally, internal responses formatted as Umami CSV can be ingested as analytics events, exposing internal data to the attacker. The vulnerability does not allow direct code execution or denial of service but can facilitate further attacks by revealing internal network details.

Mitigation Recommendations

No official fix or patch is available at the time of publication. Users should monitor the vendor's advisory for updates. As a temporary mitigation, restrict access to the data importer functionality to trusted users only and consider network-level controls to limit the server's ability to make arbitrary outbound HTTP requests. Validate and sanitize user-supplied URLs more strictly before fetching. Avoid exposing internal response data to users.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-vmh2-9r6c-h7q4
Osv Schema Version
1.4.0
Aliases
["CVE-2026-88892"]
Database Specific Severity
MODERATE
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6abfee7ba43b0b3b89e543b5

Added to database: 10/02/2026, 17:48:43 UTC

Last enriched: 10/02/2026, 17:53:43 UTC

Last updated: 10/03/2026, 02:46:07 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses