← Zurück zur CVE-Suche

CVE-2026-71964

Beschreibung

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application-s failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user-s home directory to persist on disk and be accessed through the web interface.

CVSS 6.5EPSS 0.317%Risiko 0.67
Quelle öffnen
Veröffentlicht
2026-08-10 19:17:31
Zuletzt geändert
2026-08-11 15:17:35
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N