HIGHVulnerability
CVE-2026-71965
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system.
Properties
- severity
- HIGH
- score
- 8.8
- epss_score
- 0.00345
- cve_id
- CVE-2026-71965
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-10T20:17:32.580
- last_modified
- 2026-09-08T20:32:39.347
- epss_percentile
- 0.27419
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Insufficient Verification of Data Authenticity
Explore deeper with Ninja Signal's threat intelligence graph