CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 20:17
Updated : 2026-09-08 20:32
NVD link : CVE-2026-71965
Mitre link : CVE-2026-71965
CVE.ORG link : CVE-2026-71965
JSON object : View
Products Affected
No product.
CWE
CWE-345
Insufficient Verification of Data Authenticity
