CVE-2026-34234Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated Remote Code Execution (RCE) because it performs the install.lock check only after including and executing form handler files, leaving installer endpoints reachable on already-installed instances. The handlers also pass unsanitized user input directly into shell commands, allowing an attacker to submit crafted requests that execute arbitrary commands on the server. The vulnerability stems from two combined weaknesses: (1) premature form handler execution before the lock file gate, and (2) unsafe use of user input in shell command construction. This issue is reported to be actively exploited in the wild. The issue has been fixed in version 1.2.0.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-19); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-06-04: 1Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-09-14: 1Active Exploitation · 2026-05-21: 1Technical Details · 2026-05-21: 1Technical Details · 2026-09-14: 105-1905-2106-0409-14
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-191
General1
2026-05-211
Active Exploitation1
2026-06-041
Disclosure1
2026-09-141
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-34234 - critical 🚨 CtrlPanel <= 1.1.1 - Remote Code Execution > CtrlPanel versions <= 1.1.1 are vulnerable to unauthenticated Remote Code Execution (... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-34234 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-34234 as a critical unauthenticated RCE affecting CtrlPanel <= 1.1.1, links to Project Discovery's library for more details, and references Nuclei templates, but provides no exploit code, patch, or active exploitation evidence.

    010177633
    1.3K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Active Exploitation

    CVE-2026-34234 (CtrlPanel) is a critical unauthenticated RCE in the public installer endpoint. Immediate external threat, no barriers, high value See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-19/TIER_1_CVE-2026-34234.md #CyberSecurity #VulnerabilityManagement

    Post summary

    CVE‑2026‑34234 is a critical unauthenticated RCE that is reportedly being actively exploited, as indicated by the claim of an immediate external threat.

    0001067
    46 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-34234: CtrlPanel Billing Software RCE Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04k3-rz0

    Post summary

    The article announces CVE-2026-34234, an RCE vulnerability affecting CtrlPanel Billing Software, and offers guidance on how businesses should respond, but does not provide detailed technical information, exploit code, or patch specifics.

    0000021
    32 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34234 CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to un… https://www.cve.org/CVERecord?id=CVE-2026-34234

    Post summary

    The text reports that CtrlPanel versions 1.1.1 and earlier have a vulnerability in the web installer, but provides no proof of concept, exploit code, active exploitation, patch information, or detailed technical specifics.

    0000091
    57.5K followersView on X

Explore more