CVE-2026-71966

Source
https://cve.org/CVERecord?id=CVE-2026-71966
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71966.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71966
Published
2026-08-10T18:53:12.324Z
Modified
2026-08-15T04:25:24.106397726Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer
Details

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to execute arbitrary OS commands by controlling a remote server's API response. Attackers can inject malicious commands through a crafted directory name in the remote server's API response, which bypasses security middleware validation and is passed unsanitized to the OS command execution function.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71966.json",
    "cna_assigner": "VulnCheck",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "2.4.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "2.4.3"
                }
            ],
            "source": "CPE_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/usmannasir/cyberpanel

Affected ranges

Type
GIT
Repo
https://github.com/usmannasir/cyberpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71966.json"