PT-2026-69916 · Unknown · Cyberpanel
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CyberPanel version 2.4.3
Description
An authenticated remote code execution issue exists in the remote backup feature. Authenticated attackers can obtain root-level SSH access by providing a malicious remote server address. This is possible because the process for retrieving SSH public keys is unverified, allowing an attacker to write a controlled public key directly to the
/root/.ssh/authorized keys file, which grants persistent root access to the host system.Recommendations
Update CyberPanel version 2.4.3 to the version containing commit eca0c3c.
Exploit
Fix
RCE
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyberpanel