S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Sep 10, 2026

CVE-2026-87820 Scanner

CVE-2026-87820 Scanner - Information Disclosure vulnerability in CyberPanel

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-87820
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cyberpanelby usmannasir
AFFECTED< 2.4.6SAFE ✓≥ 2.4.6
Updated Sep 11, 2026View on NVD →
Detail

CyberPanel is a popular web hosting control panel that facilitates management for server administrators and website owners. It is commonly used by web hosting companies to provide users with easy access to website and server management features. CyberPanel integrates tools for domain management, website setup, and server security. It is utilized in environments that require efficient hosting solutions tailored for both individuals and businesses. The platform aims to streamline web hosting processes while providing powerful administrative capabilities.

The Information Disclosure vulnerability arises from the exposure of debugging endpoints that can be accessed without authentication. In the affected versions, unauthenticated endpoints reveal administrator usernames, API-key prefixes, and other sensitive data. These endpoints are mistakenly left open, which compromises the confidentiality and security of the platform. By exploiting this vulnerability, attackers can gather detailed information about the system. The unauthorized exposure of such information can lead to further security breaches, making it a critical issue to address.

The technical details of the vulnerability involve the exposure of AI Scanner debug endpoints. These endpoints, accessible without proper authentication, return sensitive data. Key vulnerable areas include the '/api/ai-scanner/list-api-keys' endpoint where attackers can retrieve critical admin information. The disclosed data includes administrator names and activity logs. Additionally, these endpoints allow viewing of API key prefixes, which can be leveraged for unauthorized access. Proper endpoint security and authentication checks are missing, leading to this vulnerability.

If exploited by malicious actors, this vulnerability can lead to unauthorized access and potential system compromise. Attackers can gather reconnaissance data to conduct targeted attacks. The leakage of administrator details can aid in social engineering or brute-force attacks to gain further access. It also poses a significant risk to privacy and security of multi-tenant installations. Additionally, malicious users can monitor activities and manipulate configurations, leading to broader security implications for affected hosts.

REFERENCES

Solution Advice
  • Upgrade to CyberPanel version 2.4.6 or later to rectify the information disclosure vulnerability.
  • Implement stricter access controls and authentication mechanisms for all endpoints.
  • Regularly review and audit system configurations to detect and resolve exposure risks.
  • Monitor network traffic for unusual activity that may indicate unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-87820 Scanner - Information Disclosure vulnerability in CyberPanel | S4E