Impact
CyberPanel before version 2.4.4 fails to record audit logs for operations that can alter the child domain list. As a result, an authenticated user with privileges to manage child domains could modify, add, or delete domain entries without any trace in the application logs. This lack of accountability can conceal malicious changes that facilitate persistence or compromise other services, weakening the integrity of the configuration management process.
Affected Systems
The affected product is CyberPanel by CyberPanel. All installations of CyberPanel earlier than version 2.4.4 are vulnerable because they omit audit logging for child domain manipulation actions.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available, implying limited known exploitation activity. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to be able to authenticate to the CyberPanel control panel with privileges that allow child domain management. With such access, the attacker can perform changes that remain invisible to the system’s audit trail, potentially enabling further compromise or service disruption.
OpenCVE Enrichment