PT-2026-42016 · Ctrlpanel · Ctrlpanel

Published

2026-05-19

·

Updated

2026-05-21

·

CVE-2026-34234

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CtrlPanel versions prior to 1.2.0
Description The web-based installer at the endpoint "public/installer/index.php" allows unauthenticated Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine. The issue occurs because the system executes form handler files before verifying the install.lock file, keeping installer endpoints accessible even after installation. Additionally, these handlers pass unsanitized user input directly into shell commands. This issue is reported to be actively exploited in the wild.
Recommendations Update to version 1.2.0.

Exploit

Fix

RCE

Improper Access Control

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-34234

Affected Products

Ctrlpanel