PatchSiren cyber security CVE debrief
CVE-2026-34241 Ctrlpanel-gg CVE debrief
CVE-2026-34241 is a stored cross-site scripting vulnerability in CtrlPanel’s ticket reply notification flow. Unsanitized reply content is saved into notification payloads and later rendered unescaped in recipients’ browsers, enabling script execution in the victim’s session context. The issue affects CtrlPanel 1.1.1 and earlier and is fixed in 1.2.0.
- Vendor
- Ctrlpanel-gg
- Product
- panel
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-24
Who should care
CtrlPanel operators, hosting providers, and anyone managing ticket workflows should pay attention. Admin accounts are especially at risk because a low-privileged user can target administrators, and the reverse path also allows a compromised admin to target end users.
Technical summary
According to the advisory, the ticket reply content field ($newmessage) is stored directly and later output with Blade’s unescaped {!! !!} rendering in both App\Notifications\Ticket\Admin\AdminReplyNotification and App\Notifications\Ticket\User\ReplyNotification. This creates stored XSS in the notification UI, allowing arbitrary JavaScript to run when the notification is viewed. The NVD entry lists CVSS 3.1 vector AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N and a CWE-79 classification.
Defensive priority
High. This is internet-reachable, requires only low privileges plus a user view action, and can lead to session compromise and unauthorized administrative actions. Prioritize patching and notification rendering review.
Recommended defensive actions
- Upgrade CtrlPanel to version 1.2.0 or later.
- Review ticket notification templates for any remaining unescaped output of user-controlled content.
- Verify that reply content is HTML-escaped before storage or rendering, especially in notification payloads.
- Audit admin and user ticket notification paths for similar stored XSS patterns.
- Treat existing sessions as potentially exposed if the vulnerable version was in use and investigate suspicious account actions.
Evidence notes
The CVE record and NVD detail identify the issue as CVE-2026-34241. The GitHub security advisory and CtrlPanel 1.2.0 release are the provided source references indicating the fix. The supplied description states the vulnerability affects 1.1.1 and earlier and is corrected in 1.2.0. NVD metadata also lists CWE-79 and the CVSS vector AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34241 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34241
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34241 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34241
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0
-
Source reference
Unverified legacy reference
URL: https://github.com/Ctrlpanel-gg/panel/security/advisories/GHSA-cmrr-q3hw-3vqh
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.