Arbitrary File Read Vulnerability in CyberPanel by ISPConfig
CVE-2026-71964
What is CVE-2026-71964?
CyberPanel version 2.4.3 contains a significant vulnerability within its file manager component. This flaw allows authenticated attackers to read sensitive files on the server. The vulnerability arises due to the application’s failure to properly validate symbolic links during the extraction of ZIP archives. An attacker can exploit this by uploading a specially crafted ZIP file that contains symbolic links, enabling them to access arbitrary system files beyond their home directory. This can lead to unauthorized exposure of confidential information through the web interface.
Affected Version(s)
cyberpanel 0 <= 2.4.3
cyberpanel 0 <= 2.4.3
cyberpanel eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
