References https://nvd.nist.gov/vuln/detail/CVE-2021-45466 https://www.cvedetails.com/cve/CVE-2021-45466/ https://github.com/advisories/GHSA-cmwh-95wf-h584 https://control-webpanel.com/changelog https://octagon.net/blog/2022/01/22/cve-2021-45467-cwp-centos-web-panel-preauth-rce/ https://www.bleepingcomputer.com/news/security/cwp-bugs-allow-code-execution-as-root-on-linux-servers-patch-now/ https://thehackernews.com/2022/01/critical-bugs-in-control-web-panel.html https://cloud.tencent.com/developer/article/1938435 https://access.redhat.com/security/cve/cve-2021-45466
Related VulnerabilitiesPoCCVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code ExecutionPoCCVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug DisclosurePoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCprodigy-panel: Prodigy Annotation Tool - Unauthenticated ExposurePoCctrlpanel-installer: CtrlPanel Installer ExposurePoCmybb-installer: MyBB Installation Panel - DetectPoCosticket-installer: osTicket Installer Panel - DetectPoCopcache-control-panel: Opcache control Panel - Unauthenticated AccessPoClaravel-nova-unauth: Laravel Nova - Unauthenticated Admin Panel AccessPoCcpanel-mailman-xss: cPanel Mailman - Cross-Site ScriptingPoCCVE-2026-41940: cPanel & WHM - Authentication Bypass via Session-File CRLF InjectionPoCcPanel & WHM 权限绕过漏洞(CVE-2026-41940)PoCCVE-2024-13055: Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting