PT-2026-71705 · Unknown · Cyberpanel

·

CVE-2026-67614

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberPanel versions prior to 3.0.0
Description The WebTerminal FastAPI SSH service contains a hard-coded JSON Web Token (JWT) secret. This allows unauthenticated remote attackers to forge valid authentication tokens by signing them with the hard-coded secret value. By specifying the ssh user variable as root, an attacker can authenticate to the terminal service via WebSocket on port 8888 without valid credentials to obtain an interactive root shell.
Recommendations Update CyberPanel to version 3.0.0 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67614

Affected Products

Cyberpanel