Impact
A hard‑coded JSON Web Token secret in CyberPanel’s WebTerminal FastAPI SSH service allows an attacker to forge a valid JWT that authenticates as root. The forged token bypasses all credential checks, enabling an interactive root shell over WebSocket, which is a clear Remote Code Execution vulnerability (CWE‑798).
Affected Systems
CyberPanel from usmannasir, versions earlier than 3.0.0 are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 categorises the flaw as Critical. The EPSS score is not available, and this issue is not listed in the CISA KEV catalog. Exploitation requires only network reachability to port 8888; an unauthenticated attacker can craft the JWT and obtain a root shell without prior access or credentials. The potential impact is full system compromise.
OpenCVE Enrichment