CVE-2026-41473
published 2026-04-24CVE-2026-41473: CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote…
PriorityP268critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.77%
51.1th percentile
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cyberpanel | cyberpanel | < 2.4.4 | 2.4.4 |
| usmannasir | cyberpanel | < 2.4.4 | 2.4.4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
usmannasir cyberpanel up to 2.4.3 API Endpoint status-webhook missing authentication
vuldb·2026-04-25·CVSS 8.8
CVE-2026-41473 [HIGH] usmannasir cyberpanel up to 2.4.3 API Endpoint status-webhook missing authentication
A vulnerability was found in usmannasir cyberpanel up to 2.4.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/ai-scanner/status-webhook of the component API Endpoint. This manipulation causes missing authentication.
The identification of this vulnerability is CVE-2026-41473. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-xvg9-fp4q-jq9w: CyberPanel versions prior to 2
ghsa_unreviewed·2026-04-24
CVE-2026-41473 [HIGH] CWE-306 GHSA-xvg9-fp4q-jq9w: CyberPanel versions prior to 2
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-24
Published