Description
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
Published: 2026-09-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Insufficient Logging for Child Domain Manipulation
Action: Assess Impact
AI Analysis

Impact

CyberPanel before version 2.4.4 omits audit logging for actions that can alter the child domain list. This flaw allows a user with sufficient privileges to add, modify, or delete child domains without creating any trace in the application logs, thereby erasing accountability for configuration changes and integrity of the hosting environment.

Affected Systems

All installations of CyberPanel by CyberPanel running versions earlier than 2.4.4 are affected.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while an EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to require authenticated access to the control panel with child domain management rights, and no publicly known exploitation activity has been reported.

Generated by OpenCVE AI on September 15, 2026 at 18:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CyberPanel to version 2.4.4 or later to restore audit logging for child domain modifications.
  • Restrict child domain management permissions to only those users who absolutely need them, applying the principle of least privilege.
  • Configure external logging or integrate with a SIEM solution so that changes to child domains are recorded outside the application and can be monitored for anomaly.
  • Periodically review the records of child domain changes and set up alerts for unexpected modifications to detect potential compromise early.

Generated by OpenCVE AI on September 15, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Missing Audit Logs for Child Domain Modifications

Tue, 15 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Missing Audit Logs for Child Domain Modifications

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Insufficient Logging for Child Domain Manipulation in CyberPanel

Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient Logging for Child Domain Manipulation in CyberPanel

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
First Time appeared Cyberpanel
Cyberpanel cyberpanel
Weaknesses CWE-778
CPEs cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
Vendors & Products Cyberpanel
Cyberpanel cyberpanel
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Cyberpanel Cyberpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:18:43.832Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-29812

cve-icon Vulnrichment

Updated: 2026-09-14T18:18:37.253Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T20:16:51.157

Modified: 2026-09-16T13:42:47.857

Link: CVE-2026-29812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses