• Sources: research write-up, HN submission
  • Summary: Researchers report that the HS256 signing key for CyberPanel's WebTerminal was a string literal in the source tree and identical on every install from 2.4.2 through 2.4.6, and that the WebSocket handler reads the account to log in as from the token's own ssh_user claim, so any reachable port 8888 on those versions is an interactive root shell with no credentials and no failed-login trail. Versions 2.4.7 through 2.4.9 and 3.0.0 generate the secret per install, so reaching root on those releases means chaining CVE-2026-67613, which the write-up states is scored as requiring an authenticated administrator, making that path a privileged-admin-to-root escalation rather than an unauthenticated one. The researchers state the maintainer confirmed only 3.0.1 closes the full chain, while NVD metadata reads before 3.0.0, and the write-up cites the VulnCheck CNA record, the NVD entry for CVE-2026-67614 and CyberPanel coordinated-disclosure issue 1858 as its primaries.
  • Why it matters: The fully unauthenticated root shell is confined to 2.4.2 through 2.4.6, and teams that upgraded to 3.0.0 on the strength of the published version range still need 3.0.1 to close the chain.

send feedback on this story