Tag
critical
advisory
CyberPanel Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-65917)
3 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-65917, exists in CyberPanel versions through 1.9.1, specifically within the IncBackups application's incremental-backup handlers, allowing authenticated panel users to exploit attacker-controlled IncJob integer IDs to access, read metadata from, delete, or trigger unauthorized restoration of other tenants' backup resources, potentially leading to operations with root privileges.
CyberPanel
vulnerability
idor
web-panel
privilege-escalation
data-manipulation
3t
1c
high
advisory
CyberPanel Missing Authorization Vulnerability Allows Cross-Tenant Backup Manipulation
1 rule 2 TTPs 1 CVEA missing authorization vulnerability, identified as CVE-2026-65916, in CyberPanel through version 1.9.1 allows authenticated users to manipulate and destroy other tenants' backups by sending crafted POST requests to the `cancelBackupCreation` handler.
CyberPanel
web-vulnerability
authorization-bypass
data-destruction
cve
1r
2t
1c