Unknown · Cyberpanel · CVE-2026-71965
**Name of the Vulnerable Software and Affected Versions**
CyberPanel version 2.4.3
**Description**
An authenticated remote code execution issue exists in the remote backup feature. Authenticated attackers can obtain root-level SSH access by providing a malicious remote server address. This is possible because the process for retrieving SSH public keys is unverified, allowing an attacker to write a controlled public key directly to the `/root/.ssh/authorized keys` file, which grants persistent root access to the host system.
**Recommendations**
Update CyberPanel version 2.4.3 to the version containing commit eca0c3c.