Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/penteraio/cve-2026-41473-cyberpanel-ai-scanner-unauth
Vulnerability ScannersWeb Vulnerability ScannersVulnerability AnalysisAPI Security TestingWeb SecurityAPI Security
GitHubpenteraio/cve-2026-41473-cyberpanel-ai-scanner-unauth

CVE-2026-41473-CyberPanel-AI-Scanner-Unauth

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP probes to confirm missing authentication.

View Repository
223 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-41473 — CyberPanel AI Scanner Unauthenticated Read/Write API Access

Nuclei detection template for CVE-2026-41473 affecting CyberPanel versions before 2.4.4.

Vulnerability

CyberPanel's AI Scanner feature exposes two API endpoints without authentication:

EndpointMethodImpact
/api/ai-scanner/list-api-keysGETDiscloses admin usernames, API key prefixes, hosted domain names, and scan IDs
/api/ai-scanner/callbackPOSTAccepts arbitrary writes to scan history without authentication

Both endpoints sit under the /api/* URL prefix, which CyberPanel's secMiddleware unconditionally exempts from session authentication checks. No token, session cookie, or credentials of any kind are required to reach either endpoint.

The read endpoint enables target enumeration. The write endpoint enables scan history corruption and, when chained with the stored XSS in the AI Scanner dashboard (CVE-2026-41472), achieves unauthenticated remote code execution via cron job manipulation.

CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — 9.8 Critical

CWE: CWE-306 (Missing Authentication for Critical Function)

Fixed in: CyberPanel 2.4.4 (commit 8eb29181cb137baa4adb4bba5dce60f601d55a5f)

How the Template Works

The template sends two requests:

Request 1 — GET /api/ai-scanner/list-api-keys Confirms the target is a CyberPanel instance with the AI Scanner feature enabled and the read endpoint unprotected. Matches on the JSON structure (api_keys, recent_scans, is_payment_configured) with HTTP 200. Extracts admin usernames, API key prefixes, domain names, and scan IDs as named outputs.

Request 2 — POST /api/ai-scanner/callback with empty body {} Probes the write endpoint without performing any real write. An empty body means no scan_id is present, so the server cannot match or modify any existing ScanHistory record. On a vulnerable server (< 2.4.4), the auth check is skipped and Django returns HTTP 400 with scan_id in the error body — the server reached input validation without ever enforcing authentication. On a patched server (≥ 2.4.4), the X-API-Key header check fires first and returns HTTP 401 before scan_id is ever read.

The match requires all of:

  • Request 1: HTTP 200 + CyberPanel AI Scanner JSON structure
  • Request 2: HTTP 400 + scan_id in response body + application/json content type

This combination confirms CyberPanel AI Scanner logic was reached on both requests with no authentication enforced, while ruling out WAF blocks, reverse proxy errors, and unrelated 400 responses.

Usage

nuclei -t cyberpanel-aisscanner-unauth-rw-cve-2026-41473.yaml -u https://target:8090
# Against a list of targets
nuclei -t cyberpanel-aisscanner-unauth-rw-cve-2026-41473.yaml -l targets.txt

Affected Versions

VersionStatus
CyberPanel < 2.4.4 with AI ScannerVulnerable
CyberPanel ≥ 2.4.4Patched
CyberPanel without AI Scanner moduleNot affected

CyberPanel instances without the AI Scanner feature (generally versions before 2.3) will not match — the list-api-keys endpoint will return 404 and the template will not fire.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41473
  • Fix commit: https://github.com/usmannasir/cyberpanel/commit/8eb29181cb137baa4adb4bba5dce60f601d55a5f
  • Related: CVE-2026-41472 (stored XSS via unauthenticated callback — same fix commit)
Download Tool