← volver
CVE-2026-67614criticalCWE-798

CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.3epss 0.6%
probabilidad de explotación
0.6%top 57% de las CVE
explotación observada
noninguna fuente lo reporta
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
usmannasir · cyberpanel