CVE-2026-87820
Deferred Deferred - Pending Action

CyberPanel AI Scanner Debug Endpoint Exposure

Vulnerability report for CVE-2026-87820, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
usmannasir cyberpanel From 2.4.3 (inc) to 2.4.5 (inc)
usmannasir cyberpanel 2.4.6
usmannasir cyberpanel 3.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87820 is an information disclosure vulnerability in CyberPanel versions 2.4.3 through 2.4.5. It exposes unauthenticated AI Scanner debugging endpoints that reveal sensitive data like administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Attackers can enumerate panel administrators and scanner activity without authentication.

Detection Guidance

To detect this vulnerability, check if your CyberPanel instance is running versions 2.4.3 through 2.4.5. Use commands like 'curl -X GET http://<your-server-ip>/api/ai-scanner/list-api-keys' or 'curl -X POST http://<your-server-ip>/api/ai-scanner/test-auth' to test for exposed endpoints. If these return sensitive data without authentication, the system is vulnerable.

Verify the CyberPanel version with 'cat /usr/local/CyberPanel/version' or check the admin panel. If the version is below 2.4.6, the system is likely affected.

Impact Analysis

This vulnerability allows unauthenticated attackers to gather critical information about your CyberPanel installation. They can identify administrators, API keys, scan targets, and system configurations. This data could be used to plan further attacks, such as privilege escalation or targeted exploits against your infrastructure.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection standards like GDPR and HIPAA due to unauthorized exposure of sensitive user and system information. It demonstrates a failure to protect personally identifiable information and system metadata, which could result in regulatory penalties and loss of trust.

Mitigation Strategies

Immediately upgrade CyberPanel to version 2.4.6 or later (including 3.0.1) to patch the vulnerability. Follow the official CyberPanel update instructions or use package managers like 'apt' or 'yum' to apply the update.

If upgrading is not immediately possible, restrict access to the vulnerable endpoints by configuring a firewall or web application firewall to block requests to /api/ai-scanner/list-api-keys and /api/ai-scanner/test-auth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87820. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart