ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41473
+1 in the same advisory: …41472
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote atta

CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • cyberpanel cyberpanel
CVE-2024-53376
+1 in the same advisory: …56112
CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submi

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

NVD description · AI analysis pending
8.8
group max
11% PoC ×2
  • cyberpanel cyberpanel
CVE-2024-54679
CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

NVD description · AI analysis pending
6.5<1% PoC
  • cyberpanel cyberpanel
CVE-2024-51568
Unauthenticated command injection RCE in CyberPanel File Manager upload

CVE-2024-51568 is an unauthenticated operating-system command injection (CWE-78) in CyberPanel before 2.3.5, in the File Manager upload endpoint (/filemanager/upload). The flaw occurs when user-supplied input (completePath) is passed unsanitized into the ProcessUtilities.outputExecutioner() command-execution sink, so an attacker who submits a crafted upload request containing shell metacharacters can have arbitrary commands executed with no authentication and no user interaction. Successful exploitation yields full remote code execution on the affected server, giving the attacker control of the hosting node and everything it serves or manages. All CyberPanel installations older than 2.3.5 are affected, with the greatest risk on internet-exposed servers. A public proof-of-concept is available and the flaw carries a high exploitation probability (EPSS 45.5%, 99th percentile), though it is not yet listed in CISA KEV.

Do: Upgrade CyberPanel to version 2.3.5 or later immediately, as this fixes the command injection. Until patched, restrict network access to the CyberPanel management interface and the /filemanager/upload endpoint to trusted source IPs (firewall/allowlist), and check for signs of compromise such as unexpected processes, cron jobs, or uploaded webshells given the high exploitation probability.

9.846% PoC
  • CyberPanel before 2.3.5
largetens of thousands of internet-exposed CyberPanel instances
CVE-2024-51378
+1 in the same advisory: …51567
Unauthenticated Command Injection in CyberPanel

CyberPanel versions through 2.3.6, and 2.3.7 before commit 1c0c6cb, contain an OS command injection flaw (CWE-78) in the getresetstatus functions of dns/views.py and ftp/views.py. Because the security middleware (secMiddleware) only enforces authentication on POST requests, a remote unauthenticated attacker can send a GET request to /dns/getresetstatus or /ftp/getresetstatus and inject shell metacharacters into the statusfile parameter, executing arbitrary commands as the service. Successful exploitation yields full command execution on the hosting server with high impact to confidentiality, integrity, and availability (CVSS 9.8). Any internet-exposed CyberPanel instance, commonly used by web hosts to manage DNS and FTP services, is affected. The flaw was mass-exploited in the wild in October 2024 by the PSAUX ransomware group against roughly 22,000 CyberPanel instances, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-04 with ransomware use confirmed.

Do: Upgrade CyberPanel to a build that includes commit 1c0c6cb or later (2.3.7 alone is unpatched), per vendor instructions, or discontinue/restrict use of the product per CISA's KEV required action. Check web access logs for GET requests to /dns/getresetstatus and /ftp/getresetstatus from unauthenticated sources and review servers for PSAUX ransomware indicators. If immediate patching is not possible, restrict panel endpoints to trusted networks and block unauthenticated GET access to the affected routes.

9.895% KEV ransomware PoC ×2
  • CyberPersons CyberPanel through 2.3.6 and unpatched 2.3.7 (all builds prior to commit 1c0c6cb)
large≈20,000–30,000 internet-exposed CyberPanel instances (PSAUX attacks hit ~22,000 instances)
CVE-2019-13056
An issue was discovered in CyberPanel through 1.8.4.

An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.

NVD description · AI analysis pending
8.8<1% PoC
  • cyberpanel cyberpanel