CVE-2021-47949Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files like database credentials, and execute arbitrary shell commands through the /websites/fetchFolderDetails endpoint.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-10: 2Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-10
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - CyberPanel Command Execution via Symlink (CVE-2021-47949) A vulnerability in CyberPanel 2.1 allows authenticated attackers to execute remote code and read arbitrary files. By manipulating the completeStartingPath parameter in the file manager controller, an attacker can perform a symlink attack to access sensitive data (like database credentials) and execute shell commands through the fetch folder endpoint. 👉 Affected: CyberPanel 2.1 | Upgrade to 2.1.2 version

    Post summary

    CVE-2021-47949 enables authenticated attackers to perform remote code execution in CyberPanel through a symlink attack, and the advisory recommends upgrading to version 2.1.2 to patch the issue.

    0000060
    176 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2021-47949 CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink at… https://www.cve.org/CVERecord?id=CVE-2021-47949

    Post summary

    The text announces that CyberPanel 2.1 has a command‑execution flaw enabling authenticated attackers to read arbitrary files and run remote code through symlink exploitation.

    0000060
    57.5K followersView on X

Explore more