Path Traversal Vulnerability in CyberPanel Affects File Security
CVE-2026-67613

6.9MEDIUM

Key Information:

Vendor

Usmannasir

Vendor
CVE Published:
13 August 2026

What is CVE-2026-67613?

CyberPanel versions prior to 3.0.0 are susceptible to a path traversal vulnerability that enables authenticated administrators to inadvertently access any file on the server's filesystem. By submitting unsanitized file paths through the cloudAPI ReadReport endpoint, attackers can manipulate the reportFile parameter in the JSON request body, resulting in unauthorized file reads. This flaw allows for potential exposure of sensitive information, including credential files and SSL/SSH private keys, by bypassing necessary validation checks in the cloudManager.py script.

Affected Version(s)

cyberpanel 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deniz Mert
.