CVE-2026-29811
moderateFlawed alias-domain check in CyberPanel enables cross-account site tampering
CyberPanel before 2.4.4 contains an incorrect-comparison flaw (CWE-1025) in its logic for detecting alias domains: it attempts the check via an ORM query filter instead of a straightforward Python string comparison, so the alias-detection test can be defeated or bypassed when a domain is created or configured. A low-privileged authenticated user of the panel can trigger this during domain/website setup to make a domain resolve or map in ways the broken check should have prevented. The CVSS vector (PR:L, S:C, I:H) indicates the main impact is high integrity across the security scope — i.e., tampering with resources belonging to other tenants on the same server, such as another user's site configuration or content — with no confidentiality or availability impact. All CyberPanel installations running versions prior to 2.4.4 are affected. There is no known public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade to CyberPanel 2.4.4 or later, which fixes the alias-detection logic. On multi-tenant panels, audit domain and alias records as well as vhost configuration files for entries created by low-privilege accounts that map to domains or sites owned by other users. As a hardening measure, restrict access to the panel login (VPN or IP allowlisting) and review panel logs for suspicious domain-creation activity.
| CyberPanel (LiteSpeed Technologies) CyberPanel | before 2.4.4 (all versions prior to 2.4.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
- Weakness
- CWE-1025
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.