Description
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
Published: 2026-09-13
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized domain alias creation
Action: Upgrade
AI Analysis

Impact

CyberPanel versions before 2.4.4 attempt to determine whether a domain is an alias of another by using an ORM query filter rather than a Python 'if' statement. This incorrect logic can cause a legitimate domain to be misidentified as an alias. Consequently, an attacker who can submit domain information may create a domain that serves the same content as a primary domain without proper authorization. The flaw is mapped to CWE-1025.

Affected Systems

The affected product is CyberPanel; all releases older than version 2.4.4 are vulnerable. No sub‑version constraints are listed beyond the major revision point.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be able to submit domain data through the application, which typically requires administrative privileges or sufficient rights to manage domains. Once such privileges are obtained, creating an unauthorized alias would be straightforward due to the incorrect ORM query; however, overall risk remains limited until the necessary privileges are in reach.

Generated by OpenCVE AI on September 15, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CyberPanel to version 2.4.4 or later to apply the corrected alias detection logic
  • Verify that all existing domain configurations are correct after the update, ensuring no unintended aliases remain
  • Continuously monitor domain management logs for unexpected alias entries and remove any unauthorized ones

Generated by OpenCVE AI on September 15, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Incorrect Alias Detection Enabling Unauthorized Domain Aliases in CyberPanel

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Incorrect Alias Detection Enabling Unauthorized Domain Aliases in CyberPanel

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Flawed Alias Detection Logic in CyberPanel Allows Unauthorized Domain Aliasing
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Flawed Alias Detection Logic in CyberPanel Allows Unauthorized Domain Aliasing

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Cyberpanel
Cyberpanel cyberpanel
Weaknesses CWE-1025
CPEs cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
Vendors & Products Cyberpanel
Cyberpanel cyberpanel
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}


Sun, 13 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
References

Subscriptions

Cyberpanel Cyberpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:15:38.129Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-29811

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:51.372Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T20:16:51.020

Modified: 2026-09-16T13:42:45.977

Link: CVE-2026-29811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-1025

    Comparison Using Wrong Factors