Description
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
Published: 2026-09-13
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Insufficient Logging for Child Domain Manipulation
Action: Assess Impact
AI Analysis

Impact

CyberPanel before version 2.4.4 fails to record audit logs for operations that can alter the child domain list. As a result, an authenticated user with privileges to manage child domains could modify, add, or delete domain entries without any trace in the application logs. This lack of accountability can conceal malicious changes that facilitate persistence or compromise other services, weakening the integrity of the configuration management process.

Affected Systems

The affected product is CyberPanel by CyberPanel. All installations of CyberPanel earlier than version 2.4.4 are vulnerable because they omit audit logging for child domain manipulation actions.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available, implying limited known exploitation activity. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to be able to authenticate to the CyberPanel control panel with privileges that allow child domain management. With such access, the attacker can perform changes that remain invisible to the system’s audit trail, potentially enabling further compromise or service disruption.

Generated by OpenCVE AI on September 14, 2026 at 03:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CyberPanel to version 2.4.4 or later to re‑enable audit logging for child domain modification actions.
  • If an immediate upgrade is not possible, enable additional logging by exporting configuration changes to external log files or integrating with a centralized log management system so that domain alterations can be tracked.
  • Regularly review the records of child domain changes and, where possible, integrate alerts with a SIEM solution to detect anomalous activity promptly.
  • Apply the principle of least privilege by restricting child domain management rights to only those users who require them.

Generated by OpenCVE AI on September 14, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient Logging for Child Domain Manipulation in CyberPanel

Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
First Time appeared Cyberpanel
Cyberpanel cyberpanel
Weaknesses CWE-778
CPEs cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
Vendors & Products Cyberpanel
Cyberpanel cyberpanel
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Cyberpanel Cyberpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-13T19:52:43.151Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-29812

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-13T20:16:51.157

Modified: 2026-09-13T20:16:51.157

Link: CVE-2026-29812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T03:30:17Z

Weaknesses