CVE-2026-87820
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 09, 2026
Vendor
unknown
Description
CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.