Critical severity9.1NVD Advisory· Published Apr 24, 2026· Updated Aug 11, 2026
CVE-2026-41473
CVE-2026-41473
Description
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*range: <2.4.4
- (no CPE)range: <2.4.4
Patches
Vulnerability mechanics
References
3- itsrez.re/post/cyberpanel-rcenvdExploitMitigationThird Party Advisory
- www.vulncheck.com/advisories/cyberpanel-unauthenticated-api-access-via-ai-scanner-endpointsnvdThird Party Advisory
- github.com/usmannasir/cyberpanel/commit/8eb29181cb137baa4adb4bba5dce60f601d55a5fnvd
News mentions
0No linked articles in our index yet.