CVE 8.8 HIGH

CyberPanel < 2.4.4 Unauthenticated API Access via AI Scanner Endpoints_CVE-2026-41473

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Description

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

AI Analysis

Unauthenticated API access via AI Scanner endpoints allows remote attackers to write arbitrary data to the database, causing denial of service, corrupting scan history records, and polluting database fields with malicious data.

Basic Information

ID CVE-2026-41473
Source VulnCheck
Published Apr 24, 2026 at 20:40

Affected Product

Vendor usmannasir
Product cyberpanel
Affected Versions usmannasir cyberpanel 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor usmannasir
Product CyberPanel
Version < 2.4.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.