Path Traversal Vulnerability in CyberPanel Affects File Security
CVE-2026-67613
6.9MEDIUM
What is CVE-2026-67613?
CyberPanel versions prior to 3.0.0 are susceptible to a path traversal vulnerability that enables authenticated administrators to inadvertently access any file on the server's filesystem. By submitting unsanitized file paths through the cloudAPI ReadReport endpoint, attackers can manipulate the reportFile parameter in the JSON request body, resulting in unauthorized file reads. This flaw allows for potential exposure of sensitive information, including credential files and SSL/SSH private keys, by bypassing necessary validation checks in the cloudManager.py script.
Affected Version(s)
cyberpanel 0
