Authenticated Command Injection in CyberPanel by Usman Nasir
CVE-2026-71966

8.7HIGH

Key Information:

Vendor

Usmannasir

Vendor
CVE Published:
10 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-71966?

CyberPanel version 2.4.3 is susceptible to an authenticated command injection vulnerability associated with its remote backup transfer functionality. This flaw enables authenticated attackers to execute arbitrary OS commands by manipulating the API response from a remote server. By crafting a malicious directory name in the API response, attackers can circumvent the security middleware's validation measures, which leads to unsanitized input being executed through the OS command execution function. This vulnerability highlights the critical need for secure coding practices and proper input validation in API responses to prevent unauthorized command execution.

Affected Version(s)

cyberpanel 0 <= 2.4.3

cyberpanel 0 <= 2.4.3

cyberpanel eca0c3cbeb35af8eaae9fafb094e8ef3cd923643

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

McSam
.