CVE-2026-41472Disclosure(cyberpanel / cyberpanel)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cyberpanel cyberpanel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cyberpanel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cyberpanel

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-08-22: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-08-22: 104-2404-2508-22
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-08-221
Patch1
Full discourse3 posts
  • The Daily Tech Feed@dailytechonx
    Patch

    Heads up: serious pre-auth #RCE chain discovered in CyberPanel’s AI Scanner lets attackers obtain server shell without any login. Keywords like CVE-2026-41472, exposed API, stored XSS, cron abuse, pre-auth exploit all play major roles. If you’re running CyberPanel prior to 2.4.4, update ASAP or disable those endpoints. #Cybersecurity #RCE #CyberPanel #AI #WebHosting #Vulnerabilities https://thedailytechfeed.com/critical-ai-scanner-flaws-in-cyberpanel-let-hackers-obtain-full-server-shell/

    Post summary

    A pre‑authentication remote‑code‑execution vulnerability (CVE‑2026‑41472) was disclosed in CyberPanel’s AI Scanner, allowing shell access via exposed APIs and XSS; users are urged to update to 2.4.4 or disable the vulnerable endpoints.

    0000067
    658 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41472 Unauthenticated Stored XSS in CyberPanel AI Scanner Dashboard Below 2.4.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41472

    Post summary

    The text announces a CVE-2026-41472 unauthenticated stored XSS in CyberPanel AI Scanner Dashboard for versions below 2.4.4, with no PoC, exploit, or patch details provided.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41472 CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint la… https://www.cve.org/CVERecord?id=CVE-2026-41472

    Post summary

    The message discloses a stored XSS flaw in CyberPanel’s AI Scanner dashboard affecting pre‑2.4.4 releases, with no evidence of PoC, exploit code, or active abuse, but notes that upgrading to 2.4.4 removes the vulnerability.

    0000055
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcyberpanelcyberpanel---

Explore more