CVE-2026-71964
Received Received - Intake

Arbitrary File Read in CyberPanel via Malicious ZIP Symlink

Vulnerability report for CVE-2026-71964, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: VulnCheck

Description

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application's failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user's home directory to persist on disk and be accessed through the web interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyberpanel cyberpanel 2.4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CyberPanel 2.4.3 has an arbitrary file read vulnerability in its file manager. Authenticated attackers can exploit this by uploading a malicious ZIP archive containing symbolic links. The application fails to validate these symlinks before extraction, allowing them to read sensitive system files outside the user's home directory through the web interface.

Detection Guidance

To detect this vulnerability, check for suspicious ZIP uploads in CyberPanel's file manager. Look for files with unusual symbolic links or unexpected file paths. Review logs for unauthorized file access attempts or unusual file reads.

Impact Analysis

This vulnerability allows attackers to read sensitive system files, potentially exposing confidential data like passwords, configuration files, or other restricted information. If exploited, it could lead to further attacks, data breaches, or unauthorized access to critical system resources.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR, HIPAA, or other regulations by enabling unauthorized access to sensitive personal or health data. Organizations may face legal penalties, reputational damage, and loss of trust due to data exposure resulting from this flaw.

Mitigation Strategies

Immediately update CyberPanel to the latest version or apply the fix from commit eca0c3c. Disable file manager uploads if not needed. Restrict file upload permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71964. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart