← Voltar à pesquisa de CVEs

CVE-2026-65917

CyberPanel

Descrição

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application-s incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants- backup resources by supplying an attacker-controlled globally sequential IncJob integer ID that is never re-scoped to the authorized domain. Attackers can enumerate sequential backup IDs to read another tenant-s backup metadata, irrecoverably delete another tenant-s backup snapshots, or trigger unauthorized restoration of another tenant-s backup job with root privileges.

CVSS 8.8EPSS 0.356%Risco 0.91
Ver fonte
Publicação
2026-07-23 16:17:55
Versões afetadas
<1.9.1
Tipo
Aplicação web
Última alteração
2026-07-27 17:16:40
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H