CVE-2026-65916

Source
https://cve.org/CVERecord?id=CVE-2026-65916
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65916.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-65916
Published
2026-07-23T15:53:05.934Z
Modified
2026-07-28T03:56:05.552231478Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
CyberPanel Missing Authorization in cancelBackupCreation Handler
Details

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65916.json",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

Git / github.com/usmannasir/cyberpanel

Affected ranges

Type
GIT
Repo
https://github.com/usmannasir/cyberpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.9.1"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

Other
single_mysql
v1.*
v1.7
v1.8.7
v1.8.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65916.json"