# CVE-2024-24621

## Summary

- **CVE ID:** CVE-2024-24621
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-697
- **Published:** Jul 25, 2024
- **Last Modified:** Mar 13, 2026

## Description

Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.

## Affected Products

- Softaculous — Webuzo (3.2.1)

## References

- [CNA](https://blog.exodusintel.com/2024/07/25/softaculous-webuzo-authentication-bypass/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.16%
- **EPSS Percentile:** 65.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._