CVE-2026-29812
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-778
- Published
- 2026-09-13
- Last modified
- 2026-09-14
Affected products
- CyberPanel CyberPanel
Weakness type
Related vulnerabilities
- CVE-2024-48967 — Life2000 ventilator and Service PC lack sufficient audit logging capabilities
- CVE-2026-32693 — Unauthorized access to Kubernetes secrets in Juju
- CVE-2026-76208 — phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
- CVE-2026-25598 — Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
- CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
- CVE-2025-32967 — OpenEMR doesn't log password administration properly
- CVE-2023-1995 — Insufficient Logging Vulnerability in HiRDB