CVE-2026-41473
CyberPanel < 2.4.4 Unauthenticated API Access via AI Scanner Endpoints
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
| CWE | CWE-306 |
| Vendor | usmannasir |
| Product | cyberpanel |
| Published | Apr 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for usmannasir cyberpanel
Be the first to know when new unknown vulnerabilities affecting usmannasir cyberpanel are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
usmannasir / cyberpanel
0 < 2.4.4
References
Credits
Djibril Mounkoro