CVE-2026-87820: Usmannasir CyberPanel

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.

Affected products

  • Usmannasir CyberPanel: from 2.4.3, before 2.4.6 (fixed in 2.4.6)

Published 2026-09-09. Last modified 2026-09-14.