{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cyberpanel--2.4.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-71965"},{"cvss":8.8,"id":"CVE-2026-71966"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CyberPanel (2.4.3)","CyberPanel (\u003c= 2.4.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["CyberPanel"],"content_html":"\u003cp\u003eCyberPanel version 2.4.3 is vulnerable to an authenticated remote code execution flaw within its remote backup management functionality. The vulnerability arises from an insecure implementation of SSH public key retrieval, where the application fails to validate the source of remote server configurations. An authenticated attacker can supply a malicious remote server address to the backup service, which then retrieves an attacker-controlled public key and writes it directly to the '/root/.ssh/authorized_keys' file. This provides the attacker with persistent root-level SSH access to the underlying host system. This vulnerability was addressed in commit eca0c3c. Defenders should prioritize auditing CyberPanel configurations and ensuring updates to versions beyond 2.4.3 are applied to mitigate the risk of unauthorized persistence.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to the CyberPanel management interface using compromised or registered credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the remote backup configuration settings.\u003c/li\u003e\n\u003cli\u003eThe attacker provides a malicious remote server address in the backup target field.\u003c/li\u003e\n\u003cli\u003eThe application initiates an SSH connection to the attacker-controlled server to retrieve backup configuration files.\u003c/li\u003e\n\u003cli\u003eThe attacker's server delivers a payload containing a public SSH key disguised as part of the backup process.\u003c/li\u003e\n\u003cli\u003eThe CyberPanel application process, running with elevated privileges, writes the received public key to the '/root/.ssh/authorized_keys' file.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes an SSH session to the host system using the corresponding private key.\u003c/li\u003e\n\u003cli\u003eThe attacker obtains full, persistent root access to the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability grants an attacker full root-level persistence on the CyberPanel host. This facilitates complete system compromise, including the potential for data exfiltration, service disruption, and lateral movement within the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate CyberPanel to a version containing the fix for CVE-2026-71965 (commit eca0c3c).\u003c/li\u003e\n\u003cli\u003eMonitor file access events for changes to the '/root/.ssh/authorized_keys' file on servers running CyberPanel.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the CyberPanel interface to trusted IP ranges to prevent unauthorized authentication.\u003c/li\u003e\n\u003cli\u003eImplement host-based monitoring to detect unexpected SSH key injections in critical system directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:37:05Z","date_published":"2026-08-10T21:37:02Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cyberpanel-rce/","summary":"CyberPanel version 2.4.3 contains an authenticated remote code execution vulnerability in its remote backup feature that allows an attacker to inject an SSH public key into the root user's authorized_keys file.","title":"Authenticated Remote Code Execution in CyberPanel","url":"https://feed.craftedsignal.io/briefs/2026-08-cyberpanel-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - CyberPanel (\u003c= 2.4.3)","version":"https://jsonfeed.org/version/1.1"}