FAIL › dossier
CyberPanel
PRODUCT· dossier confidence 80%
CyberPanel is a web hosting control panel software product with a critical security posture characterized by repeated critical RCE and authentication bypass vulnerabilities in default configurations and recent releases.
PROFILE
CategorySoftwareWhat they doCyberPanel is a web hosting control panel software product.
SECURITY POSTURE
Critical security posture with repeated critical RCE and authentication bypass vulnerabilities in default configurations and recent releases.
Notable failures
- CVE-2024-51567: Unauthenticated RCE via incorrect default permissions
- CVE-2024-51378: Authentication bypass and RCE via shell metacharacters
- CVE-2026-41473: Authentication bypass in versions prior to 2.4.4
Patterns: Repeated critical RCE vulnerabilities in default configurations; Authentication bypass via shell metacharacters
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-11-07 | CVE-2024-51567 | critical | CyberPanel's incorrect default permissions allowed unauthenticated remote attackers to execute commands as root, leading to active exploitation and ransomware incidents. |
| 2024-12-04 | CVE-2024-51378 | critical | CyberPanel's incorrect default permissions allow authentication bypass and arbitrary command execution via shell metacharacters in the statusfile property. |
| 2026-04-24 | CVE-2026-41473 | critical | CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerabilit |
| 2026-04-24 | CVE-2026-41473 | critical | CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerabilit |
| 2024-10-29 | CVE-2024-51378 | critical | CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) |
| 2024-10-29 | CVE-2024-51567 | critical | CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before |
| 2024-10-29 | CVE-2024-51567 | critical | CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before |
| 2024-10-29 | CVE-2024-51378 | critical | CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) |
Open questions: Company founding date and headquarters location · Company size and ownership structure · Official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:58:11.780323+00:00