CVE-2026-71965

Source
https://cve.org/CVERecord?id=CVE-2026-71965
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71965.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71965
Published
2026-08-10T18:52:40.271Z
Modified
2026-08-15T04:25:24.051096607Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
Details

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "2.4.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "2.4.3"
                }
            ],
            "source": "CPE_FIELD"
        }
    ],
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-345"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71965.json"
}
References

Affected packages

Git / github.com/usmannasir/cyberpanel

Affected ranges

Type
GIT
Repo
https://github.com/usmannasir/cyberpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71965.json"