Impact
CyberPanel 2.4.3 contains an authenticated command injection flaw in the starRemoteTransfer backup feature, which allows an authenticated user to craft a directory name that the remote server’s API returns. That directory name is passed unsanitized to an OS command execution function, enabling arbitrary command execution on the server. The vulnerability provides an attacker with full control over the affected host, raising confidentiality, integrity, and availability risks.
Affected Systems
CVE‑2026‑71966 affects the CyberPanel web hosting control panel produced by usmannasir, specifically version 2.4.3. No other versions are listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires valid user credentials with permission to invoke the remote transfer function, but the exploitation path is straightforward because the API response is not sanitized. An attacker who can log in to CyberPanel and trigger the backup transfer can inject malicious commands by manipulating the directory name field, leading to remote code execution.
OpenCVE Enrichment