/Vulnerability Library

CtrlPanel <= 1.1.1 - Remote Code Execution

CVE-2026-34234
Verified

Description

CtrlPanel versions <= 1.1.1 are vulnerable to unauthenticated Remote Code Execution (RCE) via the web installer endpoint (public/installer/index.php). The installer loaded and executed form handler files before checking for the install.lock gate, allowing attackers to reach installer forms on fully-deployed instances. User-supplied POST values (url, key, clientkey) from the Pterodactyl configuration form were interpolated directly into shell command strings executed via bash -c without sanitization, enabling command injection. The vulnerability is confirmed actively exploited in the wild.

Severity

Critical

CVSS Score

10

Exploit Probability

5%

Affected Product

ctrlpanel

Published Date

September 14, 2026

Template Author

ritikchaddha

CVE-2026-34234.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-34234
CWE ID:
cwe-78

References

https://github.com/Ctrlpanel-gg/panel/security/advisories/GHSA-jmhr-q9q5-fqwhhttps://github.com/rootdirective-sec/CVE-2026-34234-Labhttps://github.com/Ctrlpanel-gg/panel/releases/tag/1.2.0https://nvd.nist.gov/vuln/detail/CVE-2026-34234

Remediation Steps

Update to CtrlPanel v1.2.0 or later. The patch moves the install.lock check to the top of index.php before any form files are loaded, and replaces string-based proc_open() calls with array-style argument lists to prevent shell injection. As an immediate mitigation, deny web server access to the /installer/ directory.