CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request body, which is passed directly to open() in cloudManager.py without validation or allowlisting, enabling traversal to any file readable by the root-privileged CyberPanel process including credential files, SSL and SSH private keys, and JWT secret files.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usmannasir
Usmannasir cyberpanel |
|
| Vendors & Products |
Usmannasir
Usmannasir cyberpanel |
Thu, 13 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request body, which is passed directly to open() in cloudManager.py without validation or allowlisting, enabling traversal to any file readable by the root-privileged CyberPanel process including credential files, SSL and SSH private keys, and JWT secret files. | |
| Title | CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T17:09:05.229Z
Reserved: 2026-07-29T21:07:39.203Z
Link: CVE-2026-67613
No data.
Status : Received
Published: 2026-08-13T18:18:08.197
Modified: 2026-08-13T18:18:08.197
Link: CVE-2026-67613
No data.
OpenCVE Enrichment
Updated: 2026-08-13T19:30:03Z