Impact
CyberPanel 2.4.3 contains an authenticated command injection flaw (CWE‑78) in the starRemoteTransfer backup feature. An attacker who can log in to CyberPanel can craft a directory name that the remote server’s API returns; the name is passed unsanitized to an OS command execution function, resulting in arbitrary command execution on the host. This vulnerability grants the attacker full control, compromising confidentiality, integrity, and availability.
Affected Systems
CVE‑2026‑71966 affects the CyberPanel web hosting control panel produced by usmannasir, specifically version 2.4.3. No other versions are listed as impacted in the CNA data.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. The EPSS score is 2%, and the flaw is not listed in the CISA KEV catalog. The attack requires valid user credentials with permission to invoke the remote transfer function, but the exploitation path is straightforward because the API response is not sanitized. An attacker who can log in to CyberPanel and trigger the backup transfer can inject malicious commands by manipulating the directory name field, leading to remote code execution.
OpenCVE Enrichment