---
id: CVE-2026-71964
title: >-
  CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read
  vulnerability in the file manager component that allows authenticated
  attackers to read sensitive system files by uploading a crafted ZIP archive
  containing symbo…
summary: >-
  CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read
  vulnerability in the file manager component that allows authenticated
  attackers to read sensitive system files by uploading a crafted ZIP archive
  containing symbo…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-59
published: '2026-08-10'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71964'
references:
  - url: >-
      https://github.com/usmannasir/cyberpanel/commit/eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
    label: disclosure@vulncheck.com
  - url: 'https://themcsam.github.io/posts/cyberpanel-2.4.3-vulnerabilties/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cyberpanel-arbitrary-file-read-via-file-manager-zip-upload
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00317
epssPercentile: 0.24917
ingestedAt: '2026-09-08T21:11:12.273Z'
---

## Overview

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application's failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user's home directory to persist on disk and be accessed through the web interface.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
