CVE-2026-67614: critical vulnerability in usmannasir cyberpanel
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
Published · Updated
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
usmannasir · cyberpanelRelated CVEs — usmannasir cyberpanel
In the same product, most dangerous first.
CVE-2026-71966HIGHCyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransferEPSS 3.3%CVE-2026-41473HIGHCyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner EndpointsEPSS 1.1%CVE-2026-87820MEDIUMCyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI ScannerEPSS 0.9%CVE-2026-88895HIGHCyberPanel before 3.0.5 Authentication Bypass via APIEPSS 0.7%CVE-2026-41472MEDIUMCyberPanel < 2.4.5 Stored XSS via AI Scanner DashboardEPSS 0.6%CVE-2026-65917HIGHCyberPanel IncBackups IDOR via Sequential Backup IDEPSS 0.5%