PatchSiren

CyberPanel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CyberPanel CVE published 2026-09-23

CVE-2026-79306

CVE-2026-79306 is a path traversal vulnerability in CyberPanel v1.9.1, allowing an authenticated remote attacker with domain ownership to disclose arbitrary readable files through the /filemanager/controller endpoint. The vulnerability arises from inadequate validation and canonicalization of file paths in the compress method, enabling attackers to supply absolute or out-of-scope file paths. This could le [truncated]

HIGH Cyberpanel CVE published 2026-05-10

CVE-2021-47949

CVE-2021-47949 describes an authenticated command-execution issue in CyberPanel 2.1 tied to symlink abuse in the filemanager controller. According to the supplied description, an attacker can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files such as database credentials, and then reach remote code execution through /web [truncated]