CVE-2026-41473: CyberPanel < 2.4.4 Unauthenticated API Access via AI Scanner Endpoints
CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CyberPanelto a version that resolves this vulnerability.Fixed in 2.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41473?
CVE-2026-41473 is classified as a critical vulnerability due to its potential for allowing unauthenticated remote access to the database.
How do I fix CVE-2026-41473?
To fix CVE-2026-41473, upgrade CyberPanel to version 2.4.4 or later, which addresses this authentication bypass issue.
Who is affected by CVE-2026-41473?
CVE-2026-41473 affects all versions of CyberPanel prior to 2.4.4, allowing unauthorized access to the AI Scanner API endpoints.
What types of attacks can CVE-2026-41473 enable?
CVE-2026-41473 allows attackers to write arbitrary data to the database, potentially leading to data integrity issues or further exploitation.
How can I identify if my system is vulnerable to CVE-2026-41473?
You can identify if you are vulnerable to CVE-2026-41473 by checking the CyberPanel version installed on your system and comparing it to version 2.4.4.