Skip to content
COOEY

FAIL › dossier

CyberPanel

PRODUCT

· dossier confidence 80%

CyberPanel is a web hosting control panel software product with a critical security posture characterized by repeated critical RCE and authentication bypass vulnerabilities in default configurations and recent releases.

PROFILE
CategorySoftwareWhat they doCyberPanel is a web hosting control panel software product.
SECURITY POSTURE

Critical security posture with repeated critical RCE and authentication bypass vulnerabilities in default configurations and recent releases.

Notable failures
  • CVE-2024-51567: Unauthenticated RCE via incorrect default permissions
  • CVE-2024-51378: Authentication bypass and RCE via shell metacharacters
  • CVE-2026-41473: Authentication bypass in versions prior to 2.4.4
Patterns: Repeated critical RCE vulnerabilities in default configurations; Authentication bypass via shell metacharacters
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2024-11-07 CVE-2024-51567 critical CyberPanel's incorrect default permissions allowed unauthenticated remote attackers to execute commands as root, leading to active exploitation and ransomware incidents.
2024-12-04 CVE-2024-51378 critical CyberPanel's incorrect default permissions allow authentication bypass and arbitrary command execution via shell metacharacters in the statusfile property.
2026-04-24 CVE-2026-41473 critical CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerabilit
2026-04-24 CVE-2026-41473 critical CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerabilit
2024-10-29 CVE-2024-51378 critical CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel)
2024-10-29 CVE-2024-51567 critical CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before
2024-10-29 CVE-2024-51567 critical CVE-2024-51567: upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before
2024-10-29 CVE-2024-51378 critical CVE-2024-51378: getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel)
Open questions: Company founding date and headquarters location · Company size and ownership structure · Official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:58:11.780323+00:00