Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-41473 +1 in the same advisory: …41472 | CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote atta CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2024-53376 +1 in the same advisory: …56112 | CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submi CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI. NVD description · AI analysis pending | 8.8 group max | 11% | PoC ×2 |
| — | |
| CVE-2024-54679 | CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-51568 | Unauthenticated command injection RCE in CyberPanel File Manager upload CVE-2024-51568 is an unauthenticated operating-system command injection (CWE-78) in CyberPanel before 2.3.5, in the File Manager upload endpoint (/filemanager/upload). The flaw occurs when user-supplied input (completePath) is passed unsanitized into the ProcessUtilities.outputExecutioner() command-execution sink, so an attacker who submits a crafted upload request containing shell metacharacters can have arbitrary commands executed with no authentication and no user interaction. Successful exploitation yields full remote code execution on the affected server, giving the attacker control of the hosting node and everything it serves or manages. All CyberPanel installations older than 2.3.5 are affected, with the greatest risk on internet-exposed servers. A public proof-of-concept is available and the flaw carries a high exploitation probability (EPSS 45.5%, 99th percentile), though it is not yet listed in CISA KEV. Do: Upgrade CyberPanel to version 2.3.5 or later immediately, as this fixes the command injection. Until patched, restrict network access to the CyberPanel management interface and the /filemanager/upload endpoint to trusted source IPs (firewall/allowlist), and check for signs of compromise such as unexpected processes, cron jobs, or uploaded webshells given the high exploitation probability. | 9.8 | 46% | PoC |
| largetens of thousands of internet-exposed CyberPanel instances | |
| CVE-2024-51378 +1 in the same advisory: …51567 | Unauthenticated Command Injection in CyberPanel CyberPanel versions through 2.3.6, and 2.3.7 before commit 1c0c6cb, contain an OS command injection flaw (CWE-78) in the getresetstatus functions of dns/views.py and ftp/views.py. Because the security middleware (secMiddleware) only enforces authentication on POST requests, a remote unauthenticated attacker can send a GET request to /dns/getresetstatus or /ftp/getresetstatus and inject shell metacharacters into the statusfile parameter, executing arbitrary commands as the service. Successful exploitation yields full command execution on the hosting server with high impact to confidentiality, integrity, and availability (CVSS 9.8). Any internet-exposed CyberPanel instance, commonly used by web hosts to manage DNS and FTP services, is affected. The flaw was mass-exploited in the wild in October 2024 by the PSAUX ransomware group against roughly 22,000 CyberPanel instances, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-04 with ransomware use confirmed. Do: Upgrade CyberPanel to a build that includes commit 1c0c6cb or later (2.3.7 alone is unpatched), per vendor instructions, or discontinue/restrict use of the product per CISA's KEV required action. Check web access logs for GET requests to /dns/getresetstatus and /ftp/getresetstatus from unauthenticated sources and review servers for PSAUX ransomware indicators. If immediate patching is not possible, restrict panel endpoints to trusted networks and block unauthenticated GET access to the affected routes. | 9.8 | 95% | KEV ransomware PoC ×2 |
| large≈20,000–30,000 internet-exposed CyberPanel instances (PSAUX attacks hit ~22,000 instances) | |
| CVE-2019-13056 | An issue was discovered in CyberPanel through 1.8.4. An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — |