CVE-2026-41473
CVE-2026-41473 is a critical-severity vulnerability in Cyberpanel with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-306.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- CVSS v4: 8.8
- EPSS exploit prediction: 1% (53rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-25631
- Weakness: CWE-306
- Affected product: Cyberpanel
- Published:
- Last modified:
Description
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
Frequently asked questions
- What is CVE-2026-41473?
- CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
- How severe is CVE-2026-41473?
- CVE-2026-41473 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability high.
- Is CVE-2026-41473 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (53rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-41473?
- CVE-2026-41473 affects Cyberpanel. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-41473?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-41473 have an EU (EUVD) identifier?
- Yes. CVE-2026-41473 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-25631.
- When was CVE-2026-41473 published?
- CVE-2026-41473 was published on 2026-04-24 and last updated on 2026-08-11.
References
- https://github.com/usmannasir/cyberpanel/commit/8eb29181cb137baa4adb4bba5dce60f601d55a5f
- https://itsrez.re/post/cyberpanel-rce
- https://www.vulncheck.com/advisories/cyberpanel-unauthenticated-api-access-via-ai-scanner-endpoints
EU advisories (EUVD)
Affected products (1)
- cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
More vulnerabilities in Cyberpanel
- CVE-2024-51568 — Critical (CVSS 10.0): CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the…
- CVE-2024-51567 — Critical (CVSS 10.0): upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to…
- CVE-2024-51378 — Critical (CVSS 10.0): getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers…
- CVE-2024-53376 — High (CVSS 8.8): CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the…
- CVE-2019-13056 — High (CVSS 8.8): An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's…
- CVE-2026-41472 — Medium (CVSS 6.1): CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard…
All CVEs affecting Cyberpanel →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-20357 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team…
- CVE-2026-58115 — Critical (CVSS 10.0): A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running…
- CVE-2026-63508 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to…
- CVE-2026-56163 — Critical (CVSS 10.0): Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to…
- CVE-2026-64812 — Critical (CVSS 10.0): In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- CVE-2026-60644 — Critical (CVSS 10.0): Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →