---
id: CVE-2026-67613
title: >-
  CyberPanel before 3.0.0 contains a path traversal vulnerability that allows
  authenticated administrators to read arbitrary files from the server
  filesystem by supplying unsanitized file paths to the cloudAPI ReadReport
  endpoint
summary: >-
  CyberPanel before 3.0.0 contains a path traversal vulnerability that allows
  authenticated administrators to read arbitrary files from the server
  filesystem by supplying unsanitized file paths to the cloudAPI ReadReport
  endpoint. Attacker…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-13'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67613'
references:
  - url: 'https://cyberpanel.net/KnowledgeBase/home/change-logs/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/usmannasir/cyberpanel/issues/1858'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cyberpanel-path-traversal-file-read-via-cloudapi-readreport
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00498
epssPercentile: 0.40125
ingestedAt: '2026-09-08T21:11:12.277Z'
---

## Overview

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request body, which is passed directly to open() in cloudManager.py without validation or allowlisting, enabling traversal to any file readable by the root-privileged CyberPanel process including credential files, SSL and SSH private keys, and JWT secret files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
