Executive brief
CyberPanel is a web hosting control panel used by hosting providers and administrators to manage websites and server resources. A missing return statement in access control logic allows the application to execute unintended code paths, potentially bypassing security checks and allowing unauthorized operations on hosted websites and accounts.
Technical details
CyberPanel before version 2.4.4 contains a control flow vulnerability in its access control list (ACL) logic where a required "return 0" statement was omitted from the business logic. This missing return statement causes the code to continue executing past a security check that should have terminated early, potentially allowing an attacker to bypass access restrictions. The vulnerability affects the acl.py module responsible for enforcing permission boundaries. Exploitation requires network access to the CyberPanel interface; authenticated access may be required depending on the specific affected code path. The vulnerability was fixed in version 2.4.4 by restoring the proper control flow.
Affected products
- CyberPanel CyberPanel before 2.4.4
Timeline
- 2026-09-13: disclosed
- 2026-09-13: patched: Fixed in version 2.4.4