CVE-2026-79306
Last modified
CVE-2026-79306 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with attacker-controlled basePath and compressedFileName values, in a method=compress request. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-scope file paths in the listOfFiles JSON property, together with attacker-controlled basePath and compressedFileName values, in a method=compress request. Because the application validates only domain ownership and does not canonicalize or restrict these paths to the authorized site directory, the backend appends them to zip or tar archive commands and executes them as the website externalApp user, allowing disclosure of arbitrary readable files through the generated archive.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-79306?
How severe is CVE-2026-79306?
How do I fix CVE-2026-79306?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-79294Cross Site Scripting vulnerability in Moonshot AI Kimi versi…6.1
- CVE-2026-79298An issue in Howyar Technologies Inc SysReturn Versions prior…8.4
- CVE-2026-7930Rejected reason: Is not a vulnerability, is a feature bug.
- CVE-2026-79300SEP sesam before 5.2.0.24 mishandles User Authorization with…3.5
- CVE-2026-79303kaiten from 57.192.20 to before 57.214.26 is vulnerable to S…9.9
- CVE-2026-79304CyberPanel 1.9.1 contains a path traversal vulnerability in …6.5
- CVE-2026-7931Insufficient validation of untrusted input in iOS in Google …5.4
- CVE-2026-79310webpy web.py 0.76 is vulnerable to server-side template inje…8.5
- CVE-2026-79311webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS…
- CVE-2026-79312webpy web.py 0.76 is vulnerable to Session Fixation. The com…6.8
- CVE-2026-79313webpy web.py 0.76 is vulnerable to Insufficient Session Expi…9.8
- CVE-2026-79314A horizontal privilege escalation vulnerability exists in x-…8.8
Are you affected by CVE-2026-79306?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
