PT-2026-64023 · Unknown · Cyberpanel

·

CVE-2026-65917

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberPanel versions prior to 1.9.1
Description An insecure direct object reference (IDOR) exists in the IncBackups application's incremental-backup handlers. This occurs because the system uses a globally sequential integer ID for backup jobs without verifying if the requesting user is authorized for that specific domain. Authenticated users can manipulate the IncJob variable to access backup metadata, permanently delete backup snapshots, or trigger unauthorized restoration of backup jobs with root privileges. The affected handlers are deleteBackup(), fetchRestorePoints(), and restorePoint().
Recommendations Update CyberPanel to a version containing commit b198460.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65917

Affected Products

Cyberpanel