CVE-2026-65917 is an insecure direct object reference (IDOR) vulnerability in CyberPanel's IncBackups application, allowing authenticated users to access or manipulate other tenants' backup resources. The vulnerability exists in the incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) and is caused by the use of an attacker-controlled globally sequential IncJob integer ID that [truncated]
CVE-2026-41473 is an authentication bypass vulnerability in CyberPanel versions prior to 2.4.4. The vulnerability exists in the AI Scanner worker API endpoints, specifically /api/ai-scanner/status-webhook and /api/ai-scanner/callback. This allows unauthenticated remote attackers to write arbitrary data to the database, potentially leading to denial of service through storage exhaustion, corruption of scan [truncated]
CVE-2026-41472 is a stored cross-site scripting vulnerability in CyberPanel versions prior to 2.4.4. The vulnerability exists in the AI Scanner dashboard and is caused by the POST /api/ai-scanner/callback endpoint lacking authentication, allowing unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. This vulnerability can lead to remote cod [truncated]