Description
CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.
Published: 2026-04-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via XSS in the AI Scanner dashboard
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw located in the AI Scanner dashboard of CyberPanel versions prior to 2.4.4. An unauthenticated attacker can POST arbitrary JavaScript to the /api/ai-scanner/callback endpoint, overwriting the findings_json field of ScanHistory records. The injected script is executed in the context of an administrator’s authenticated session when the admin visits the dashboard, enabling the attacker to issue same‑origin requests that plant cron jobs and ultimately execute code on the server. The primary impact is the ability for an attacker to obtain remote code execution on the affected host.

Affected Systems

The affected product is CyberPanel by usmannasir. All releases before version 2.4.4 are vulnerable; the issue was identified in the AI Scanner feature of those builds. No specific patch level is listed beyond the noted 2.4.4 release, which contains the fix.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it is not a widely exploited or actively targeted flaw. Attackers must send a malicious POST request to an open endpoint that is accessible without authentication and then rely on an administrator visiting the AI Scanner dashboard. While the attack requires a victim to perform an administrative action, the potential for remote code execution makes it a high‑value target for an attacker willing to pursue this vector.

Generated by OpenCVE AI on April 28, 2026 at 05:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CyberPanel to version 2.4.4 or later to apply the vendor patch
  • Restrict or block access to the /api/ai-scanner/callback endpoint until a patch is applied, using firewall rules or IP‑based restrictions
  • If delayed patching, disable the AI Scanner feature or remove the endpoint from the installation to eliminate the vulnerable code path

Generated by OpenCVE AI on April 28, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Cyberpanel
Cyberpanel cyberpanel
CPEs cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
Vendors & Products Cyberpanel
Cyberpanel cyberpanel
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 28 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Usmannasir
Usmannasir cyberpanel
Vendors & Products Usmannasir
Usmannasir cyberpanel

Mon, 27 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
Description CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.
Title CyberPanel < 2.4.4 Stored XSS via AI Scanner Dashboard
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Cyberpanel Cyberpanel
Usmannasir Cyberpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-27T13:37:16.906Z

Reserved: 2026-04-20T16:07:47.312Z

Link: CVE-2026-41472

cve-icon Vulnrichment

Updated: 2026-04-27T13:37:13.558Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-24T21:16:18.967

Modified: 2026-04-28T15:45:19.903

Link: CVE-2026-41472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T09:17:46Z

Weaknesses