CVE-2026-79306 Overview
CVE-2026-79306 is a path traversal vulnerability in CyberPanel v1.9.1 affecting the compress method of the /filemanager/controller endpoint. An authenticated attacker who owns any configured domain can supply absolute or out-of-scope file paths in the listOfFiles JSON property along with attacker-controlled basePath and compressedFileName values. The backend appends these paths to zip or tar archive commands and executes them as the website externalApp user. This allows disclosure of arbitrary readable files on the host through the generated archive.
Critical Impact
Any authenticated CyberPanel user with domain ownership can read arbitrary files accessible to the site's externalApp account, including configuration files, keys, and other tenants' web content.
Affected Products
- CyberPanel v1.9.1
- CyberPanel filemanager module (filemanager/filemanager.py, filemanager/views.py)
- CyberPanel security middleware (CyberCP/secMiddleware.py)
Discovery Timeline
- 2026-09-23 - CVE-2026-79306 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-79306
Vulnerability Analysis
The vulnerability resides in the file manager compress handler exposed via the /filemanager/controller endpoint. The request accepts a JSON body containing basePath, compressedFileName, and listOfFiles. CyberPanel's access checks confirm that the calling user owns a domain but do not canonicalize or restrict the supplied paths to that domain's document root.
Because listOfFiles entries are concatenated into shell archive commands (zip or tar) and executed as the site's externalApp operating system user, an attacker can provide absolute paths pointing outside the authorized site directory. The archive command reads those files and writes them into a resulting archive that the attacker can then download. This is a Path Traversal issue [CWE-22] leading to arbitrary file disclosure.
Root Cause
Input validation in the compress workflow relies solely on domain-ownership authorization. The code paths in filemanager/filemanager.py and filemanager/views.py do not normalize listOfFiles, basePath, or compressedFileName and do not enforce a prefix check against the authorized site root. Absolute paths and path segments outside the site directory pass validation and reach the archive command unchanged.
Attack Vector
An authenticated attacker sends a POST request to /filemanager/controller with method=compress, providing a basePath and a listOfFiles array containing absolute paths such as system configuration files or files under another tenant's home directory. CyberPanel executes the archive command as the site's externalApp user and produces an archive containing the targeted files. The attacker retrieves the archive through the file manager download path.
The vulnerability manifests in the compress request handler. See the CVE technical write-up and the referenced filemanager.py compress logic for the exact code paths.
Detection Methods for CVE-2026-79306
Indicators of Compromise
- Requests to /filemanager/controller containing method=compress with listOfFiles entries that begin with / or contain ../ sequences.
- Unexpected .zip or .tar archives created in site directories owned by externalApp users, especially with attacker-chosen compressedFileName values.
- zip or tar process executions referencing paths outside the invoking site's document root.
Detection Strategies
- Inspect CyberPanel access logs for POST requests to /filemanager/controller and parse JSON bodies for absolute paths in listOfFiles.
- Correlate web request logs with auditd records for execve calls invoking zip or tar with file arguments outside the site owner's home directory.
- Alert when archives created by the file manager contain entries such as /etc/, /root/, or paths belonging to other domains.
Monitoring Recommendations
- Enable verbose logging on the CyberPanel file manager and forward JSON request bodies to a centralized log platform for parsing.
- Monitor filesystem read events on sensitive files (/etc/shadow, TLS private keys, database credentials) initiated by externalApp accounts.
- Track anomalous download activity from /filemanager/ endpoints correlated with recent compress operations.
How to Mitigate CVE-2026-79306
Immediate Actions Required
- Restrict access to the CyberPanel administrative interface to trusted networks or over VPN until a patched version is deployed.
- Audit CyberPanel user accounts and remove or disable any unnecessary domain-owner accounts to reduce the authenticated attack surface.
- Review recent file manager activity for compress operations referencing absolute or traversal paths, and rotate any credentials, keys, or secrets that may have been exposed.
Patch Information
At the time of publication, no vendor patch is referenced in the NVD entry. Monitor the CyberPanel repository for a fixed release above v1.9.1 and apply it as soon as it becomes available. Track the CVE technical reference for updated remediation guidance.
Workarounds
- Place CyberPanel behind an authenticating reverse proxy or IP allowlist so only trusted operators can reach /filemanager/controller.
- Deploy a web application firewall rule that blocks requests to /filemanager/controller where the JSON body contains method=compress combined with absolute paths or ../ sequences in listOfFiles, basePath, or compressedFileName.
- Apply strict filesystem permissions and Mandatory Access Control (for example, AppArmor or SELinux) profiles on externalApp users to prevent reads outside each site's document root.
# Example ModSecurity rule to block traversal payloads to the compress endpoint
SecRule REQUEST_URI "@beginsWith /filemanager/controller" \
"phase:2,chain,deny,status:403,id:1079306,msg:'CVE-2026-79306 CyberPanel path traversal attempt'"
SecRule REQUEST_BODY "@rx (?:\"listOfFiles\"|\"basePath\"|\"compressedFileName\")[^\]]*(?:/\.\./|\"/(etc|root|home|var)/)" \
"t:none,t:urlDecodeUni"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.