In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of… (CVE-2026-88892)
OpenPanel analytics platform contains a server-side request forgery (SSRF) vulnerability in its data importer component. The importer fetches a caller-supplied URL using a plain fetch method without applying the existing SSRF guard. Authenticated organization members can cause the server to connect to arbitrary internal or external addresses. The HTTP response status and text are stored and returned to the user, enabling internal network scanning. Additionally, if the internal response is in a specific CSV format, it can be ingested as analytics events visible to the attacker. No patched version is available at the time of publication.
AI Analysis
Technical Summary
CVE-2026-88892 affects all versions of OpenPanel. The data importer fetches URLs supplied by authenticated users using a plain fetch call instead of the project's SSRF protection utility. The URL parameter is only validated as a syntactically valid URL, allowing requests to internal IP addresses such as 127.0.0.1 or 169.254.169.254. An authenticated organization member, including those with minimal access, can exploit this to make the server perform HTTP requests to arbitrary internal or external endpoints. The server's HTTP response status and status text are saved and returned to the user, providing a feedback channel for internal network scanning. If the response is formatted as Umami CSV, it is ingested as analytics events, exposing internal data to the attacker. There is no patch or fix available at the time of disclosure.
Potential Impact
An authenticated user can exploit this SSRF vulnerability to scan internal network hosts, ports, and paths by causing the server to fetch arbitrary URLs. This can lead to information disclosure about internal infrastructure. Additionally, internal responses formatted as Umami CSV can be ingested as analytics events, exposing internal data to the attacker. The vulnerability does not allow direct code execution or denial of service but can facilitate further attacks by revealing internal network details.
Mitigation Recommendations
No official fix or patch is available at the time of publication. Users should monitor the vendor's advisory for updates. As a temporary mitigation, restrict access to the data importer functionality to trusted users only and consider network-level controls to limit the server's ability to make arbitrary outbound HTTP requests. Validate and sanitize user-supplied URLs more strictly before fetching. Avoid exposing internal response data to users.
In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of… (CVE-2026-88892)
Description
OpenPanel analytics platform contains a server-side request forgery (SSRF) vulnerability in its data importer component. The importer fetches a caller-supplied URL using a plain fetch method without applying the existing SSRF guard. Authenticated organization members can cause the server to connect to arbitrary internal or external addresses. The HTTP response status and text are stored and returned to the user, enabling internal network scanning. Additionally, if the internal response is in a specific CSV format, it can be ingested as analytics events visible to the attacker. No patched version is available at the time of publication.
CVSS v3.1
Score 5.0medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-88892 affects all versions of OpenPanel. The data importer fetches URLs supplied by authenticated users using a plain fetch call instead of the project's SSRF protection utility. The URL parameter is only validated as a syntactically valid URL, allowing requests to internal IP addresses such as 127.0.0.1 or 169.254.169.254. An authenticated organization member, including those with minimal access, can exploit this to make the server perform HTTP requests to arbitrary internal or external endpoints. The server's HTTP response status and status text are saved and returned to the user, providing a feedback channel for internal network scanning. If the response is formatted as Umami CSV, it is ingested as analytics events, exposing internal data to the attacker. There is no patch or fix available at the time of disclosure.
Potential Impact
An authenticated user can exploit this SSRF vulnerability to scan internal network hosts, ports, and paths by causing the server to fetch arbitrary URLs. This can lead to information disclosure about internal infrastructure. Additionally, internal responses formatted as Umami CSV can be ingested as analytics events, exposing internal data to the attacker. The vulnerability does not allow direct code execution or denial of service but can facilitate further attacks by revealing internal network details.
Mitigation Recommendations
No official fix or patch is available at the time of publication. Users should monitor the vendor's advisory for updates. As a temporary mitigation, restrict access to the data importer functionality to trusted users only and consider network-level controls to limit the server's ability to make arbitrary outbound HTTP requests. Validate and sanitize user-supplied URLs more strictly before fetching. Avoid exposing internal response data to users.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vmh2-9r6c-h7q4
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-88892"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abfee7ba43b0b3b89e543b5
Added to database: 10/02/2026, 17:48:43 UTC
Last enriched: 10/02/2026, 17:53:43 UTC
Last updated: 10/03/2026, 02:46:07 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.