CVE-2026-67614: falha crítica em usmannasir cyberpanel
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
Publicada em · Atualizada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.3epss 1.0%
probabilidade de exploração
1.0%top 40% das CVEs
exploração observada
nãonenhuma fonte reporta
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
usmannasir · cyberpanelCVEs relacionadas — usmannasir cyberpanel
No mesmo produto, das mais perigosas para as menos.
CVE-2026-71966HIGHCyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransferEPSS 3.3%CVE-2026-41473HIGHCyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner EndpointsEPSS 1.1%CVE-2026-87820MEDIUMCyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI ScannerEPSS 0.9%CVE-2026-88895HIGHCyberPanel before 3.0.5 Authentication Bypass via APIEPSS 0.7%CVE-2026-41472MEDIUMCyberPanel < 2.4.5 Stored XSS via AI Scanner DashboardEPSS 0.6%CVE-2026-65917HIGHCyberPanel IncBackups IDOR via Sequential Backup IDEPSS 0.5%