Vendor
CyberPanel Authentication Bypass via API
1 TTP 1 CVECyberPanel versions prior to 3.0.5 contain an authentication bypass vulnerability where two-factor authentication is not enforced on API endpoints, allowing credential-derived token misuse.
Authenticated Remote Code Execution in CyberPanel
1 rule 4 TTPs 3 CVEsCyberPanel version 2.4.3 contains an authenticated remote code execution vulnerability in its remote backup feature that allows an attacker to inject an SSH public key into the root user's authorized_keys file.
CyberPanel Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-65917)
3 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-65917, exists in CyberPanel versions through 1.9.1, specifically within the IncBackups application's incremental-backup handlers, allowing authenticated panel users to exploit attacker-controlled IncJob integer IDs to access, read metadata from, delete, or trigger unauthorized restoration of other tenants' backup resources, potentially leading to operations with root privileges.
CyberPanel 2.1 Authenticated Remote Command Execution via Symlink Exploitation (CVE-2021-47949)
2 rules 1 TTP 1 CVECyberPanel version 2.1 is vulnerable to command execution (CVE-2021-47949) where an authenticated attacker can exploit symlink attacks via the filemanager controller endpoint by manipulating the completeStartingPath parameter in POST requests, leading to sensitive file access and arbitrary shell command execution.