{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/usmannasir/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-65916"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CyberPanel (through 1.9.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","authorization-bypass","data-destruction","cyberpanel","cve"],"_cs_type":"advisory","_cs_vendors":["usmannasir"],"content_html":"\u003cp\u003eCVE-2026-65916 describes a critical missing authorization vulnerability affecting CyberPanel installations up to version 1.9.1. This flaw, fixed in commit \u003ccode\u003eb198460\u003c/code\u003e, resides within the \u003ccode\u003ecancelBackupCreation\u003c/code\u003e handler, which is intended to manage backup processes. However, due to insufficient authorization checks, any authenticated user can exploit this vulnerability to impact backups belonging to other tenants on the same CyberPanel instance. By sending specially crafted POST requests containing arbitrary \u003ccode\u003ebackupCancellationDomain\u003c/code\u003e and \u003ccode\u003efileName\u003c/code\u003e parameters, attackers can terminate backup processes, delete existing backup archives, corrupt backup status files, and remove corresponding database records for other users. This poses a significant risk of data loss and service disruption for multi-tenant CyberPanel environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains valid authentication credentials for a low-privileged account on a CyberPanel instance.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request targeting the \u003ccode\u003e/cancelBackupCreation\u003c/code\u003e endpoint of the CyberPanel web interface.\u003c/li\u003e\n\u003cli\u003eThe crafted request includes parameters \u003ccode\u003ebackupCancellationDomain\u003c/code\u003e and \u003ccode\u003efileName\u003c/code\u003e, specifying a target domain and backup file belonging to another tenant.\u003c/li\u003e\n\u003cli\u003eThe CyberPanel application, due to the missing authorization check, processes the request without verifying if the authenticated user has rights to manage backups for the specified \u003ccode\u003ebackupCancellationDomain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecancelBackupCreation\u003c/code\u003e handler executes internal commands to stop, delete, or corrupt the backup process or files associated with the targeted tenant.\u003c/li\u003e\n\u003cli\u003eThe targeted tenant's backup processes are terminated, their backup archives are deleted, their backup status files become corrupted, and related database records are removed.\u003c/li\u003e\n\u003cli\u003eThis results in significant data loss, unavailability of critical backups, and potential service disruption for the victim tenant.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-65916 can lead to severe consequences, primarily data loss and data unavailability for tenants sharing a CyberPanel installation. Attackers can completely destroy critical backup archives, making recovery from other incidents impossible. This directly impacts data integrity and availability, leading to potential business continuity failures, reputational damage, and financial losses for affected organizations. The vulnerability affects multi-tenant environments where one authenticated user can maliciously impact others.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65916 by upgrading CyberPanel to a version that includes commit \u003ccode\u003eb198460\u003c/code\u003e or later immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM to detect attempts to exploit the \u003ccode\u003ecancelBackupCreation\u003c/code\u003e handler.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003ewebserver\u003c/code\u003e logs for suspicious POST requests to the \u003ccode\u003e/cancelBackupCreation\u003c/code\u003e endpoint, especially those originating from unexpected accounts or specifying domains not owned by the requesting user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T16:19:01Z","date_published":"2026-07-23T16:19:01Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cyberpanel-auth-bypass/","summary":"A missing authorization vulnerability, identified as CVE-2026-65916, in CyberPanel through version 1.9.1 allows authenticated users to manipulate and destroy other tenants' backups by sending crafted POST requests to the `cancelBackupCreation` handler.","title":"CyberPanel Missing Authorization Vulnerability Allows Cross-Tenant Backup Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-07-cyberpanel-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Usmannasir","version":"https://jsonfeed.org/version/1.1"}