CVE-2026-41472
EUVD-2026-2563024.04.2026, 21:16
CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cyberpanel | cyberpanel | 𝑥 < 2.4.4 |
𝑥
= Vulnerable software versions