GHSA-5hg3-c77v-8mxmHighCVSS 8.8
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution...
🔗 CVE IDs covered (1)
📋 Description
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-71965
- https://github.com/usmannasir/cyberpanel/commit/eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
- https://themcsam.github.io/posts/cyberpanel-2.4.3-vulnerabilties
- https://www.vulncheck.com/advisories/cyberpanel-authenticated-rce-via-remote-backup-feature
- https://github.com/advisories/GHSA-5hg3-c77v-8mxm