What is CVE-2026-65916?
CVE-2026-65916 is a missing authorization vulnerability in CyberPanel up to version 1.9.1, fixed in commit b198460. It allows authenticated users to kill, delete, or corrupt other tenants' backups via the cancelBackupCreation handler by sending crafted POST requests. Immediate update to the patched version is required.
Azərbaycanca: CVE-2026-65916 CyberPanel-in 1.9.1 və daha əvvəlki versiyalarında aşkarlanmış missing authorization zəifliyidir. Bu, autentifikasiya olunmuş istifadəçilərə `cancelBackupCreation` handler vasitəsilə digər istifadəçilərin backup-lərini silmək, pozmaq və ya dayandırmaq imkanı verir. dərhal commit b198460 ilə yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which CyberPanel versions are affected by CVE-2026-65916?
CyberPanel versions up to and including 1.9.1 are affected by this vulnerability.
What can an authenticated user do by exploiting CVE-2026-65916?
It allows authenticated users to kill, delete, or corrupt other tenants' backups via the cancelBackupCreation handler.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.