CVE-2026-79304 Overview
CVE-2026-79304 is a path traversal vulnerability [CWE-22] in CyberPanel 1.9.1. The flaw exists in the readFileContents method of the /filemanager/controller endpoint. An authenticated attacker who owns any configured domain can supply an arbitrary absolute or out-of-scope path in the fileName JSON property. The authorization logic validates only domainName and does not canonicalize fileName against the domain's home directory. As a result, the application returns the contents of any file readable by the CyberPanel execution identity, exposing configuration files, credentials, and other sensitive data across the host.
Critical Impact
Authenticated tenants can read arbitrary files accessible to the CyberPanel process, including cross-tenant data and system secrets.
Affected Products
- CyberPanel 1.9.1
- Deployments exposing the /filemanager/controller endpoint to authenticated users
- Multi-tenant CyberPanel installations where domain owners are considered untrusted
Discovery Timeline
- 2026-09-23 - CVE-2026-79304 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-79304
Vulnerability Analysis
The /filemanager/controller endpoint accepts a JSON payload with domainName and fileName fields. The security middleware and view layer confirm that the requesting user owns the specified domainName, but perform no validation that fileName resolves inside that domain's document root. The readFileContents function passes the attacker-controlled path directly to file read operations. An attacker supplying an absolute path such as /etc/passwd or a traversal sequence like ../../ receives the raw file contents in the response. The scope covers any file readable by the CyberPanel service account, which typically includes web server configuration, database credentials, and files belonging to other tenants on the same host.
Root Cause
The root cause is missing path canonicalization and containment. The application treats domain ownership as sufficient authorization for arbitrary file paths. It does not resolve fileName with os.path.realpath and does not verify the resolved path is a descendant of the domain's home directory. Reviewers can see the affected logic in the CyberPanel File Manager Function and CyberPanel Views Implementation.
Attack Vector
Exploitation requires an authenticated session with ownership of at least one configured domain. The attacker submits a POST request to /filemanager/controller with a JSON body containing a valid domainName they control and a fileName pointing to a target path outside that domain. Because the check enforced by the security middleware only validates domain ownership, the request succeeds and the server responds with the file's contents. See the published GitHub CVE Report for the disclosed request pattern.
Detection Methods for CVE-2026-79304
Indicators of Compromise
- POST requests to /filemanager/controller where the fileName parameter contains absolute paths, ../ sequences, or references outside /home/<domain>/
- File manager responses returning contents of /etc/, /root/, or other tenants' /home/ directories
- Unexpected reads of mysql.conf, .env, or CyberPanel configuration files by the web service account
Detection Strategies
- Enable web server access logging for /filemanager/controller and alert on payloads containing traversal patterns or absolute paths in fileName
- Correlate authenticated CyberPanel sessions with file read events targeting paths that fall outside the session owner's domain home directory
- Deploy host-based auditing (auditd open and openat rules) on the CyberPanel service account to record reads of sensitive files
Monitoring Recommendations
- Baseline normal file manager access patterns per tenant and alert on deviations that touch system directories
- Monitor for bursts of file manager requests from a single account, which may indicate automated enumeration
- Forward CyberPanel and web server logs to a centralized analytics platform for retention and cross-tenant correlation
How to Mitigate CVE-2026-79304
Immediate Actions Required
- Restrict access to the CyberPanel administrative interface to trusted networks or VPN users until a patched release is deployed
- Audit tenant accounts and disable or rotate credentials for any domain owner that is not fully trusted
- Review recent /filemanager/controller requests for traversal attempts and treat matches as potential data disclosure incidents
Patch Information
No vendor patch is referenced in the enriched CVE data at the time of publication. Monitor the CyberPanel repository for updates beyond version 1.9.1 that add canonicalization and containment checks to the readFileContents method.
Workarounds
- Apply a local patch that calls os.path.realpath on the incoming fileName and rejects any path not prefixed by the requesting domain's home directory
- Run CyberPanel under a least-privilege service account so cross-tenant and system files are not readable by the process
- Place a reverse proxy or web application firewall rule in front of /filemanager/controller that blocks JSON payloads containing ../ sequences or absolute paths in fileName
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.