Impact
CyberPanel versions 2.4.3 through 2.4.5 contain unauthenticated AI Scanner debugging endpoints that reveal administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. An attacker who can reach these endpoints can enumerate panel administrators and recent scanner activity, providing valuable reconnaissance for subsequent attacks on a multi‑tenant installation.
Affected Systems
The flaw affects the CyberPanel product by usmannasir, specifically all releases from 2.4.3 up to and including 2.4.5.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. Because the attack can be performed without authentication and the EPSS score is unavailable, the likelihood of exploitation is uncertain but the vulnerability is publicly disclosed, and it is not listed in the CISA KEV catalogue. A likely attack vector is direct HTTP requests to the unprotected AI Scanner debugging endpoints exposed on the panel's web interface.
OpenCVE Enrichment