CVE-2026-67613
Received Received - Intake

Path Traversal in CyberPanel via cloudAPI ReadReport

Vulnerability report for CVE-2026-67613, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: VulnCheck

Description

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request body, which is passed directly to open() in cloudManager.py without validation or allowlisting, enabling traversal to any file readable by the root-privileged CyberPanel process including credential files, SSL and SSH private keys, and JWT secret files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyberpanel cyberpanel to 3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CyberPanel before version 3.0.0 has a path traversal vulnerability in the cloudAPI ReadReport endpoint. Authenticated administrators can read arbitrary files from the server filesystem by manipulating the reportFile parameter in JSON requests. The parameter is passed directly to open() in cloudManager.py without validation, allowing access to sensitive files like credentials, SSL/SSH keys, and JWT secrets.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to the cloudAPI ReadReport endpoint with unsanitized file paths in the reportFile parameter. Check server logs for suspicious file access attempts by the CyberPanel process. Use commands like 'grep -r "ReadReport" /var/log/' to search for relevant logs. Ensure CyberPanel is updated to version 3.0.0 or later.

Impact Analysis

An attacker with admin access could exploit this to read sensitive files on the server, including configuration files, private keys, and credentials. This could lead to further attacks like privilege escalation, data theft, or server compromise if combined with other vulnerabilities.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face compliance penalties, legal consequences, and reputational damage if exploited.

Mitigation Strategies

Immediately update CyberPanel to version 3.0.0 or later to patch the vulnerability. If updating is not possible, restrict access to the cloudAPI ReadReport endpoint and implement strict input validation for the reportFile parameter. Review file permissions to ensure the CyberPanel process cannot access sensitive files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67613. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart