CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 18:18
Updated : 2026-09-08 20:32
NVD link : CVE-2026-67614
Mitre link : CVE-2026-67614
CVE.ORG link : CVE-2026-67614
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
