CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usmannasir
Usmannasir cyberpanel |
|
| Vendors & Products |
Usmannasir
Usmannasir cyberpanel |
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system. | |
| Title | CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T17:52:07.313Z
Reserved: 2026-08-08T16:43:04.178Z
Link: CVE-2026-71965
No data.
Status : Received
Published: 2026-08-10T20:17:32.580
Modified: 2026-08-11T18:18:22.887
Link: CVE-2026-71965
No data.
OpenCVE Enrichment
Updated: 2026-08-11T03:30:03Z