CVE-2024-51567Active Exploitation(cyberpanel / cyberpanel)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for cyberpanel cyberpanel systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-11-28. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cyberpanel

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
cyberpanel

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-29: 1Active Exploitation · 2026-01-29: 1Technical Details · 2026-01-29: 101-29
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • kokumօtօ@__kokumoto
    Active Exploitation

    以下の4脆弱性がランサムウェアに悪用されたことが確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。 - Windowsの権限昇格CVE-2024-49039, CVE-2024-30088 - CyberPanelの無認証root権限RCE CVE-2024-51567 - FirefoxのRCE CVE-2024-9680 https://t.co/rE32uwR7pJ

    Post summary

    CISA has updated its catalog confirming that four CVEs—including Windows privilege‑escalation, CyberPanel root‑level RCE, and Firefox RCE—are actively exploited by ransomware. No patches, PoCs, or exploit tools are referenced.

    06038163.4K
    7.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcyberpanelcyberpanel---

Explore more