EXPOSURES › CVE-2024-51378
CVE-2024-51378
CRITICAL ⌖ ON CISA KEV · EXPLOITEDCyberPanel's incorrect default permissions allow authentication bypass and arbitrary command execution via shell metacharacters in the statusfile property.
CyberPanel shipped with incorrect default permissions that permit authentication bypass and arbitrary command execution using shell metacharacters in the statusfile property. This is a critical, actively exploited vulnerability linked to ransomware that exposes DIB organizations to data breaches and compliance failures. Organizations must immediately patch CyberPanel and restrict default configurations to prevent exploitation.
Shame score — The vendor shipped with incorrect default permissions that allow authentication bypass and arbitrary command execution, a negligent and avoidable flaw actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.