PT-2026-69917 · Unknown · Cyberpanel

·

CVE-2026-71966

·

Published

2026-08-10

·

Updated

2026-08-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberPanel version 2.4.3
Description An authenticated command injection issue exists in the remote backup transfer feature. Authenticated attackers can execute arbitrary OS commands by controlling the API response of a remote server. By providing a crafted directory name in the remote server's API response, the attacker can bypass security middleware validation, as the input is passed unsanitized to the OS command execution function.
Recommendations Update CyberPanel version 2.4.3 to the version containing commit eca0c3c.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71966

Affected Products

Cyberpanel