CVE Feed

    Dashboard / CVE / CVE-2026-41473

    CVE-2026-41473

    CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

    Published:Apr 24, 2026
    Last Modified:Aug 11, 2026
    EPS:Apr 24, 2026
    EPSS Score:0.00773
    CVSS Score:9.1

    Affected Products

    Vendor
    Cyberpanel
    Product
    Cyberpanel
    Vendor
    Usmannasir
    Product
    Cyberpanel

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High