CVE-2026-29811
7.7CyberPanel · CyberPanel
CyberPanel versions prior to 2.4.4 contain an ORM query filter flaw when detecting alias domains, potentially allowing unauthorized modifications.
Executive summary
A logic flaw in CyberPanel versions before 2.4.4 allows an authenticated attacker to manipulate domain alias configurations, posing a high risk to system integrity.
Vulnerability
The application utilizes an improper ORM query filter to identify domain aliases instead of a standard conditional check. This logic error requires a low-privileged authenticated attacker to trigger the flaw, resulting in potential integrity compromise of domain settings.
Business impact
The ability to manipulate domain alias configurations can lead to unauthorized content serving or redirection, effectively compromising the integrity of web services hosted on the platform. With a CVSS score of 7.7, this vulnerability is categorized as High, reflecting the significant impact on configuration management and the potential for service misdirection within the hosting environment.
Remediation
Immediate Action: Upgrade the CyberPanel installation to version 2.4.4 or later to implement the corrected Python logic.
Proactive Monitoring: Audit web server configuration files and domain alias settings for unexpected changes or unauthorized entries.
Compensating Controls: Ensure that administrative access to the CyberPanel dashboard is restricted to trusted internal networks to limit the pool of potential attackers.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for unauthorized alteration of domain settings, administrators should prioritize updating to version 2.4.4 immediately. While the vulnerability requires authenticated access, the high severity of the potential impact necessitates prompt remediation to maintain the security and integrity of the hosting environment.
More CyberPanel CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section