CyberPanel fixed two high-severity authorization flaws in versions through 1.9.1 that allowed authenticated users to interfere with backups belonging to other tenants. CVE-2026-65916 exposed the cancelBackupCreation handler to missing authorization checks, enabling crafted POST requests that could terminate another tenant’s backup process, delete backup archives, corrupt backup status files, and remove related database records. The issue is tracked as CWE-862 and was rated CVSS 8.1 under v3.1.
A second flaw, CVE-2026-65917, affected CyberPanel’s incremental backup handlers with a cross-tenant IDOR condition tied to globally sequential IncJob identifiers. Attackers with panel access could enumerate backup IDs to read backup metadata, delete another tenant’s snapshots, or trigger unauthorized restoration of another tenant’s backup job with root-level effects. CyberPanel addressed both issues in commit b1984603f9b0099b39bca46fea176e53b6d4d601 by adding ownership validation and re-scoping lookups for IncJob, JobSnapshots, and Backups records to the authenticated tenant’s domain.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A CyberPanel commit patched multiple cross-tenant authorization and IDOR issues in backup cancellation and incremental backup handlers. The changes added ownership validation and re-scoped backup, job, and snapshot lookups to the authenticated tenant’s domain to prevent unauthorized read, delete, restore, and cancel actions across tenants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.