CVE-2026-29811
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-1025
- Published
- 2026-09-13
- Last modified
- 2026-09-14
Affected products
- CyberPanel CyberPanel
Weakness type
Related vulnerabilities
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2025-71377 — stoatchat before 20250210-1 Unrestricted Message History Fetch
- CVE-2026-75840 — ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
- CVE-2023-54390 — PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
- CVE-2025-32464 — HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow becau
- CVE-2026-9800 — Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
- CVE-2026-48860 — Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist