Impact
CyberPanel before version 2.4.4 omits audit logging for actions that can alter the child domain list. This flaw allows a user with sufficient privileges to add, modify, or delete child domains without creating any trace in the application logs, thereby erasing accountability for configuration changes and integrity of the hosting environment.
Affected Systems
All installations of CyberPanel by CyberPanel running versions earlier than 2.4.4 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while an EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to require authenticated access to the control panel with child domain management rights, and no publicly known exploitation activity has been reported.
OpenCVE Enrichment