CVE-2026-41473 Details
Description
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
A vulnerability exists in CyberPanel versions prior to 2.4.4, allowing unauthenticated remote attackers to bypass authentication on AI Scanner worker API endpoints. This vulnerability enables attackers to write arbitrary data to the database by sending requests to the '/api/ai-scanner/status-webhook' and '/api/ai-scanner/callback' endpoints. The lack of authentication checks can be exploited to cause a denial-of-service by exhausting storage, corrupting scan history records, and contaminating database fields with malicious data.
Users are advised to update to CyberPanel version 2.4.4 or later, where this vulnerability has been fixed by implementing proper authentication and API key validation for the affected endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/usmannasir/cyberpanel/commit/8eb29181cb137baa4adb4bba5dce60f601d55a5f | [email protected] | |
| https://itsrez.re/post/cyberpanel-rce | [email protected] | ExploitMitigationThird Party Advisory |
| https://www.vulncheck.com/advisories/cyberpanel-unauthenticated-api-access-via-ai-scanner-endpoints | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cyberpanel cyberpanel | < 2.4.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | New CVE Received | [email protected] |