Junglewise Threat Intelligence

CVE-2026-87820: CyberPanel AI Scanner unauthenticated information disclosure

CVE-2026-87820 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Vendors: CyberPanel.

Executive brief

CyberPanel is a web hosting control panel used to manage multi-tenant server environments and hosted domains. Versions 2.4.3 through 2.4.5 expose debugging API endpoints without authentication, allowing attackers to enumerate administrator usernames, API-key prefixes, and scan activity metadata. An attacker can inventory all administrators and targets across the hosted panel to facilitate account takeover or lateral movement attacks.

Technical details

The vulnerability is an information disclosure (CWE-200) caused by active debug code (CWE-489) in production. Two unauthenticated endpoints—GET /api/ai-scanner/list-api-keys and POST /api/ai-scanner/test-auth—expose administrator usernames, API-key prefixes, account state, scan identifiers, target domains, and scan ownership metadata without requiring authentication or user interaction. The vulnerable endpoints are network-reachable and require no privileges. An attacker can enumerate multi-tenant installations and associate administrators with hosted domains to support reconnaissance for follow-on attacks. The fix (commit 20484fd) removes the debugging routes and their handlers; patched versions are CyberPanel 2.4.6, 3.0.1, and later stable releases.

Affected products

  • CyberPanel CyberPanel 2.4.3 through 2.4.5

Timeline

  • 2026-08-11: disclosed: GitHub Security Advisory GHSA-qmwq-9cc8-x6h2 published
  • 2026-05-04: patched: Fix committed (commit 20484fd); available in CyberPanel 2.4.6, 3.0.1 and later
  • 2026-09-09: advisory: CVE-2026-87820 published on NVD

References