CVE-2026-41473Disclosure(cyberpanel / cyberpanel)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch cyberpanel cyberpanel systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cyberpanel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-21)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
cyberpanel

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-24: 2Mentions · 2026-04-26: 1Mentions · 2026-05-21: 3Active Exploitation · 2026-04-26: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-26: 1Technical Details · 2026-05-21: 304-2404-2605-21
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-242
Disclosure2
2026-04-261
Active Exploitation1
2026-05-213
Disclosure3
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened On April 24, 2026, security researchers disclosed CVE-2026-41473, an authentication bypass vulnerability in CyberPanel (a widely deployed hosting control panel) affecting all versions prior to 2.4.4. The vulnerability exists in the AI Scanner worker API…

    Post summary

    Researchers disclosed an authentication bypass vulnerability (CVE-2026-41473) in CyberPanel versions older than 2.4.4; no PoC, exploit, patch, or evidence of active exploitation is provided.

    1001036
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CyberPanel versions before 2.4.4 contain a critical authentication bypass (CVE-2026-41473, CVSS 8.8) in their AI Scanner API endpoints that allows unauthenticated attackers to write arbitrary data to the backend database. The flaw opens the door to denial-of-service…

    Post summary

    The text discloses that CyberPanel versions prior to 2.4.4 have a critical authentication bypass in their AI Scanner API, allowing unauthenticated arbitrary database writes and potential denial‑of‑service, with a CVSS score of 8.8.

    1000030
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-41473 · < 2.4.4 → 2.4.4 TL;DR CyberPanel versions before 2.4.4 contain a critical authentication bypass (CVE-2026-41473, CVSS 8.8) in their AI Scanner API endpoints that allows unauthenticated attackers to write arbitrary data to the backend database.

    Post summary

    CyberPanel versions prior to 2.4.4 contain a critical authentication bypass (CVE‑2026‑41473, CVSS 8.8) allowing unauthenticated attackers to write arbitrary data to the backend database; the issue is resolved in version 2.4.4.

    1000044
    227 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CyberPanel CVE-2026-41473 is under active exploitation—attackers can bypass authentication via AI Scanner endpoints. CVSS 9.8. Patch now to prevent unauthorized access. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware https://t.co/3enxPEuyEQ

    Post summary

    CVE‑2026‑41473 is being actively exploited to bypass authentication in CyberPanel, and a patch is now available to prevent unauthorized access.

    0000046
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41473 Unauthenticated Authentication Bypass in CyberPanel AI Scanner API Endpoints Below 2.4.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41473

    Post summary

    CVE-2026-41473 is an unauthenticated authentication bypass vulnerability affecting CyberPanel AI Scanner API endpoints below version 2.4.4, reported on Vulmon without any PoC, exploit code, active exploitation, or patch information.

    0000058
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41473 CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers … https://www.cve.org/CVERecord?id=CVE-2026-41473

    Post summary

    The tweet announces the discovery of the authentication bypass vulnerability CVE-2026-41473 affecting CyberPanel versions prior to 2.4.4.

    0000072
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcyberpanelcyberpanel---

Explore more