Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-67614: CyberPanel WebTerminal Authentication Bypass via Websocket
CVE-2026-67614 · published 21 days ago
Summary
A vulnerability in CyberPanel's WebTerminal allows attackers to bypass authentication and gain root access. This could let unauthorized users access sensitive parts of the system. CyberPanel users should update to version 3.0.0 or later to fix this issue.
What to do
- Update usmannasir cyberpanel to version 3.0.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| usmannasir | cyberpanel | < 3.0.0 |
Original advisory text
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
References
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Monitor software like this
Free during beta