CVE-2026-29812
Received Received - Intake

CyberPanel Missing Logging for Child Domain Actions

Vulnerability report for CVE-2026-29812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: MITRE

Description

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-14
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyberpanel cyberpanel to 2.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-778 When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CyberPanel versions before 2.4.4 lack logging for actions that could modify the child domains list. This means changes to domain configurations are not recorded, potentially allowing unauthorized or malicious modifications without detection.

Detection Guidance

This vulnerability involves lack of logging for actions manipulating child domains in CyberPanel before 2.4.4. To detect it, check CyberPanel logs for any suspicious modifications to domain configurations. Look for missing entries in logs where domain changes should be recorded. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow attackers to alter domain settings without leaving a trace. It may lead to unauthorized access, domain hijacking, or disruption of services hosted on affected systems.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it involves a lack of logging for domain manipulation actions rather than unauthorized data access or disclosure. However, insufficient logging could hinder audit trails required for compliance under these regulations.

Mitigation Strategies

Upgrade CyberPanel to version 2.4.4 or later to ensure proper logging of actions related to child domains.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-29812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart