Skip to main content
Vulnerability Database/CVE-2026-79304

CVE-2026-79304: CyberPanel Path Traversal Vulnerability

CVE-2026-79304 is a path traversal flaw in CyberPanel 1.9.1 that allows authenticated attackers to read arbitrary files outside their domain directory. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-79304 Overview

CVE-2026-79304 is a path traversal vulnerability [CWE-22] in CyberPanel 1.9.1. The flaw exists in the readFileContents method of the /filemanager/controller endpoint. An authenticated attacker who owns any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. The authorization logic validates only domainName and does not canonicalize fileName against the domain's home directory. As a result, the application returns the contents of any file readable by the CyberPanel execution identity, exposing configuration files, credentials, and other sensitive data across the host.

Critical Impact

Authenticated tenants can read arbitrary files accessible to the CyberPanel process, including cross-tenant data and system secrets.

Affected Products

  • CyberPanel 1.9.1
  • Deployments exposing the /filemanager/controller endpoint to authenticated users
  • Multi-tenant CyberPanel installations where domain owners are considered untrusted

Discovery Timeline

  • 2026-09-23 - CVE-2026-79304 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-79304

Vulnerability Analysis

The /filemanager/controller endpoint accepts a JSON payload with domainName and fileName fields. The security middleware and view layer confirm that the requesting user owns the specified domainName, but perform no validation that fileName resolves inside that domain's document root. The readFileContents function passes the attacker-controlled path directly to file read operations. An attacker supplying an absolute path such as /etc/passwd or a traversal sequence like ../../ receives the raw file contents in the response. The scope covers any file readable by the CyberPanel service account, which typically includes web server configuration, database credentials, and files belonging to other tenants on the same host.

Root Cause

The root cause is missing path canonicalization and containment. The application treats domain ownership as sufficient authorization for arbitrary file paths. It does not resolve fileName with os.path.realpath and does not verify the resolved path is a descendant of the domain's home directory. Reviewers can see the affected logic in the CyberPanel File Manager Function and CyberPanel Views Implementation.

Attack Vector

Exploitation requires an authenticated session with ownership of at least one configured domain. The attacker submits a POST request to /filemanager/controller with a JSON body containing a valid domainName they control and a fileName pointing to a target path outside that domain. Because the check enforced by the security middleware only validates domain ownership, the request succeeds and the server responds with the file's contents. See the published GitHub CVE Report for the disclosed request pattern.

Detection Methods for CVE-2026-79304

Indicators of Compromise

  • POST requests to /filemanager/controller where the fileName parameter contains absolute paths, ../ sequences, or references outside /home/<domain>/
  • File manager responses returning contents of /etc/, /root/, or other tenants' /home/ directories
  • Unexpected reads of mysql.conf, .env, or CyberPanel configuration files by the web service account

Detection Strategies

  • Enable web server access logging for /filemanager/controller and alert on payloads containing traversal patterns or absolute paths in fileName
  • Correlate authenticated CyberPanel sessions with file read events targeting paths that fall outside the session owner's domain home directory
  • Deploy host-based auditing (auditd open and openat rules) on the CyberPanel service account to record reads of sensitive files

Monitoring Recommendations

  • Baseline normal file manager access patterns per tenant and alert on deviations that touch system directories
  • Monitor for bursts of file manager requests from a single account, which may indicate automated enumeration
  • Forward CyberPanel and web server logs to a centralized analytics platform for retention and cross-tenant correlation

How to Mitigate CVE-2026-79304

Immediate Actions Required

  • Restrict access to the CyberPanel administrative interface to trusted networks or VPN users until a patched release is deployed
  • Audit tenant accounts and disable or rotate credentials for any domain owner that is not fully trusted
  • Review recent /filemanager/controller requests for traversal attempts and treat matches as potential data disclosure incidents

Patch Information

No vendor patch is referenced in the enriched CVE data at the time of publication. Monitor the CyberPanel repository for updates beyond version 1.9.1 that add canonicalization and containment checks to the readFileContents method.

Workarounds

  • Apply a local patch that calls os.path.realpath on the incoming fileName and rejects any path not prefixed by the requesting domain's home directory
  • Run CyberPanel under a least-privilege service account so cross-tenant and system files are not readable by the process
  • Place a reverse proxy or web application firewall rule in front of /filemanager/controller that blocks JSON payloads containing ../ sequences or absolute paths in fileName

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.