Critical AI Scanner Flaws in CyberPanel Let Hackers Obtain Full Server Shell

CyberPanel versions before 2.4.4 are vulnerable to a serious chain of pre-authentication flaws that enable attackers to gain full server access without credentials. The exploit, discovered by Pentera researchers, hinges on misconfigurations in the AI Scanner feature and unprotected API endpoints. An attacker leveraging this chain could secretly execute commands on hosting servers, effectively achieving full takeover of resources managed via the control panel. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

How the Attack Chain Works

The vulnerability starts with an unauthenticated AI Scanner endpoint that accepts externally-sourced scan results. Since submitted content isn’t properly sanitized, malicious JavaScript may be stored persistently in the database — a stored cross-site scripting (XSS) flaw (CVE-2026-41472). ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

Submitting forged scan results requires a valid scan ID, which appeared safe — until researchers discovered another API endpoint, /api/ai-scanner/list-api-keys, exposed in debug mode. This debug endpoint doesn’t require authentication and leaks recent scan IDs. That misstep, tracked as CVE-2026-41473, gives an attacker the missing piece to submit malicious scans. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

Once the XSS payload is stored, it stays dormant until a CyberPanel administrator opens the AI Scanner results page. On that view, the malicious script executes in the admin’s browser with full access to their session and CSRF token. That allows the attacker to create a new administrator account without needing the original admin’s credentials. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

Escalation to Server Shell Access

With admin-level access, the attacker can then exploit CyberPanel’s cron job management. By creating a new site and corresponding system user account, then abusing the cronCommand parameter, attackers can run any shell command on the server. This effectively grants a complete server shell. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

The sequence shows how multiple individual vulnerabilities — unauthenticated endpoints, stored XSS, and command execution via cron jobs — can link together into a powerful remote‐code execution (RCE) exploit that doesn’t require scanning edges or low-hanging portals. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

Patching and Mitigation Steps

The flaws were responsibly disclosed on May 4, 2026, with patches released within approximately four hours. They include removing debug endpoints, enforcing authentication for callback endpoints, and ensuring proper output escaping. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

Administrators using affected CyberPanel versions should immediately update to version 2.4.4 or later. For those who can’t upgrade yet, disabling the AI Scanner feature and restricting access to sensitive API paths — especially /api/ai-scanner/list-api-keys and /api/ai-scanner/test-auth — can help reduce exposure. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

The impact of this exploit is substantial: cybercriminals exploiting it gain full control over hosting infrastructure without ever needing legitimate login credentials. ([cybersecuritynews.com](https://cybersecuritynews.com/cyberpanel-pre-auth-rce-chain-gain-server-shell/))

It’s a stark reminder that web hosting panels, often loaded with powerful server-management tools, demand careful architecture. Every endpoint—forgotten debug tools, for example—can be an avenue for compromise.

What to watch: even when patches are available, vulnerable installations linger. Enterprises should audit their server-management tools for exposed APIs, enforce strict authentication, and monitor unusual account creation or cron jobs. Proper logging, least-privilege administration, and rapid patch deployment will remain essential countermeasures in preventing similar RCE chains in the future.