CRITICAL 9.3 NVD

CVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to fo

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.

References

Published: 2026-08-13 · Source: NVD · Feed updated: 2026-08-13
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-13 via NVD.

Risk Timeline

CVE Disclosed2026-08-13 · -1 days ago

Remediation Resources

vulnfeed aggregates 10812 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.