CVE-2026-65917
CyberPanel · cyberpanel
CyberPanel is vulnerable to an authorization bypass flaw allowing attackers to access unauthorized data through user-controlled keys.
Executive summary
An authorization bypass vulnerability in CyberPanel allows authenticated users to manipulate keys to access data, posing a significant risk to system security.
Vulnerability
This vulnerability, identified as CWE-639, involves an authorization bypass through user-controlled keys. An authenticated attacker can exploit this flaw to perform unauthorized actions or access sensitive data by manipulating parameters.
Business impact
The CVSS score of 8.8 highlights the severity of this issue, as it allows for unauthorized access to critical data and functions. Such an exploit can result in severe data breaches, loss of administrative control, and potential operational disruption.
Remediation
Immediate Action: Apply the fix by updating to the version containing commit b1984603f9b0099b39bca46fea176e53b6d4d601.
Proactive Monitoring: Review audit logs for unusual patterns of access or attempts to access backup IDs that do not correlate with legitimate user activity.
Compensating Controls: Implement strict access control lists and, where possible, restrict access to the CyberPanel dashboard to trusted management networks only.
Exploitation status
Public Exploit Available: Yes, a technical advisory detailing the IDOR vulnerability has been published by VulnCheck.
Analyst recommendation
The authorization bypass vulnerability represents a critical failure in access control logic. It is imperative that administrators apply the provided fix immediately to prevent unauthorized access and protect sensitive information managed by the platform.