Critical severity9.8NVD Advisory· Published Aug 13, 2026
CVE-2026-67614
CVE-2026-67614
Description
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.0.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.