CVE-2026-71964

Source
https://cve.org/CVERecord?id=CVE-2026-71964
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71964.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71964
Published
2026-08-10T18:51:43.214Z
Modified
2026-08-15T04:25:24.106137371Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload
Details

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application's failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user's home directory to persist on disk and be accessed through the web interface.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "2.4.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "2.4.3"
                }
            ],
            "source": "CPE_FIELD"
        }
    ],
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-59"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71964.json"
}
References

Affected packages

Git / github.com/usmannasir/cyberpanel

Affected ranges

Type
GIT
Repo
https://github.com/usmannasir/cyberpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71964.json"