CVE-2024-51378

CyberPanel Incorrect Default Permissions Vulnerability

9.8
CVSS 3.1
94.7 %
EPSS (current)
2024-12-04
KEV addition
Yes
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: CyberPersons / CyberPanel

Published: 2024-10-29 · Due (CISA): 2024-12-25

CWE: CWE-78 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2024/CVE-2024-51378.yamlCyberPanel - Command Injection–
metasploitexploit/unix/webapp/cyberpanel_preauth_rce_multi_cveexploit/unix/webapp/cyberpanel_preauth_rce_multi_cve2024-10-27
exploitdb52172CyberPanel 2.3.6 - Remote Code Execution (RCE)2025-04-11

References only — no downloads or instructions.

Sources