What is CVE-2026-71964?
CyberPanel 2.4.3 contains an arbitrary file read vulnerability in the file manager component. Authenticated attackers can read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Fixed in commit eca0c3c.
Azərbaycanca: CyberPanel 2.4.3-də fayl meneceri komponentində ixtiyari fayl oxuma (arbitrary file read) boşluğu aşkar edilib. Doğrulanmış hücumçu simvolik keçid (symbolic link) olan ZIP arxivi yükləyərək sistem fayllarını oxuya bilər. eca0c3c commit-i ilə düzəldilib.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Does the attacker need to be authenticated to exploit the file read vulnerability in CyberPanel 2.4.3?
Yes, the attacker must be authenticated to exploit this vulnerability. The vulnerability was discovered in the file manager component.
In which commit was this CyberPanel vulnerability fixed?
The vulnerability was fixed in commit eca0c3c.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.