Authenticated Command Injection in CyberPanel by Usman Nasir
CVE-2026-71966
Key Information:
- Vendor
Usmannasir
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
What is CVE-2026-71966?
CyberPanel version 2.4.3 is susceptible to an authenticated command injection vulnerability associated with its remote backup transfer functionality. This flaw enables authenticated attackers to execute arbitrary OS commands by manipulating the API response from a remote server. By crafting a malicious directory name in the API response, attackers can circumvent the security middleware's validation measures, which leads to unsanitized input being executed through the OS command execution function. This vulnerability highlights the critical need for secure coding practices and proper input validation in API responses to prevent unauthorized command execution.
Affected Version(s)
cyberpanel 0 <= 2.4.3
cyberpanel 0 <= 2.4.3
cyberpanel eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
