Authentication Bypass Vulnerability in CyberPanel by Etherparty
CVE-2026-41473
Key Information:
- Vendor
Usmannasir
- Status
- Vendor
- CVE Published:
- 24 April 2026
Badges
What is CVE-2026-41473?
CyberPanel versions before 2.4.4 are exposed to an authentication bypass vulnerability that affects the AI Scanner worker API endpoints. This flaw enables unauthenticated remote attackers to gain unauthorized access and potentially write arbitrary data to the database. By manipulating requests sent to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints, attackers can exploit the absence of proper authentication checks. This could result in denial of service through storage exhaustion, corruption of scan history records, and the injection of malicious data into database fields.
Affected Version(s)
cyberpanel 0 < 2.4.4
cyberpanel 0a099b1b193946555fbdd387a28486b1521f9961
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
