SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85613

HIGH · CVSS 8.2 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

OpenPanel versions prior to 2.3.0 are vulnerable to a cross-site scripting (XSS) flaw in the unauthenticated favicon proxy endpoint, allowing remote attackers to execute scripts via malicious SVG file URLs. This vulnerability can lead to unauthorized access to authenticated endpoints by leveraging same-origin credentialed requests in victims' browsers. Organizations using OpenPanel should prioritize patching this issue to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85613
Severity
HIGH
CVSS
8.2
EPSS
0.23%

Original NVD Description

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints.