PT-2026-35084 · Unknown · Cyberpanel

Djibril Mounkoro

·

Published

2026-04-24

·

Updated

2026-05-21

·

CVE-2026-41473

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberPanel versions prior to 2.4.4
Description An authentication bypass in the AI Scanner worker API endpoints allows unauthenticated remote attackers to write arbitrary data to the database. This is achieved by sending requests to the endpoints '/api/ai-scanner/status-webhook' and '/api/ai-scanner/callback'. Exploitation of this flaw can lead to denial of service through storage exhaustion, corruption of scan history records, and pollution of database fields with malicious data.
Recommendations Update to version 2.4.4 or later.

Exploit

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41473

Affected Products

Cyberpanel