Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyberpanel
Cyberpanel cyberpanel |
|
| CPEs | cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cyberpanel
Cyberpanel cyberpanel |
Fri, 14 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usmannasir
Usmannasir cyberpanel |
|
| Vendors & Products |
Usmannasir
Usmannasir cyberpanel |
Thu, 13 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell. | |
| Title | CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T16:51:02.511Z
Reserved: 2026-07-29T21:07:39.203Z
Link: CVE-2026-67614
Updated: 2026-08-14T12:40:24.857Z
Status : Received
Published: 2026-08-13T18:18:08.370
Modified: 2026-08-14T13:19:06.033
Link: CVE-2026-67614
No data.
OpenCVE Enrichment
Updated: 2026-08-13T19:00:12Z
-
CWE-798
Use of Hard-coded Credentials