CVE-2026-34234 is an unauthenticated remote code execution vulnerability affecting CtrlPanel 1.1.1 and earlier. The web installer invokes form handlers before enforcing the installation lock check, so installer functionality can remain reachable after deployment. Affected handlers incorporate attacker-controlled input into shell command construction without appropriate neutralization and execute the resulting command through a shell. The combined access-control and command-injection flaws permit remote command execution on exposed instances.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a local Docker lab and proof-of-concept for CVE-2026-34234, an unauthenticated web-installer RCE in CtrlPanel. The repo contains two main PoC scripts in Python, a fake supporting API service, Docker orchestration for vulnerable and patched product versions, and wrapper entrypoint scripts to stabilize lab permissions. Primary exploit capability: the PoC sends an HTTP POST to /installer/index.php and abuses installer parameters, especially key, to inject shell command substitution into a vulnerable command-building path. In the vulnerable CtrlPanel 1.1.1 image, installer input is interpolated into a shell string executed via bash -c, enabling unauthenticated command execution. The included payload is intentionally benign: it runs id, whoami, and hostname, redirecting output to /var/www/html/storage/logs/cve_2026_34234_proof.txt. The patched 1.2.0 image is included for comparison and should not create the proof file. Repository structure: README.md documents the vulnerability chain, patch rationale, lab design, and usage. docker-compose.yml defines the full lab: vulnerable and patched CtrlPanel containers, separate MariaDB and Redis backends, and a fake-api service bound locally. fake-api/server.py implements minimal HTTP endpoints (/health, /api/client/account, /api/application/users) to satisfy installer checks. poc/poc_http_only.py is the main exploit script and performs only the HTTP request. poc/poc_lab.py is a helper/regression script that sends the same request and then uses docker compose exec to verify proof-file creation inside containers. vuln/Dockerfile and patched/Dockerfile wrap official CtrlPanel images, while docker/lab-entrypoint.sh repeatedly fixes permissions on storage and cache directories before invoking the original entrypoint. Overall, this is a real exploit repository, not merely a detector. It is operational but intentionally constrained to a local lab and a harmless proof payload rather than persistence, exfiltration, or shell access.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown; the content only references creation of a YAML file for CVE-2026-34234 and provides no vulnerability, affected-product, impact, or exploitation details.
An unauthenticated remote code execution vulnerability in CtrlPanel's web-based installer affecting versions 1.1.1 and prior, caused by installer endpoint exposure and unsanitized user input being passed into shell commands.
A critical unauthenticated remote code execution vulnerability in CtrlPanel's web installer caused by premature installer form handler execution combined with unsanitized shell command construction, allowing arbitrary command execution on exposed instances.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.