CVE-2026-34234
CtrlPanel, an open‑source billing platform for hosting providers, had a critical flaw that let anyone run arbitrary commands on the server. The bug was in the installer, which executed user input before checking if the software was already installed. The issue was fixed in version 1.2.0.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
CtrlPanel 1.1.1 and earlier, used by hosting providers.
Real-world impact
An attacker could run any command on the server, gaining full control, reading or deleting data, installing malware, or taking the service offline.
Why this severity
The CVSS score of 10 reflects that the flaw is exploitable from the network, requires no authentication, and gives the attacker complete control over confidentiality, integrity, and availability.
What to do about it
- 01Upgrade CtrlPanel to version 1.2.0 or later.
NVD-referenced vendor advisory
Timeline
- May 19, 2026 · May 19, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.