00Hrs
:
00Min
:
00Sec
News Security

CyberPanel v2.4.9 Released — Security & Reliability Maintenance Update

CyberPanel v2.4.9 (build 9) is out — a security & reliability maintenance release. There are no UI changes and it is safe to upgrade right away: open your panel and go to Version Management → Upgrade (take a server snapshot first). Most of these fixes were reported by our community and security researchers — thank you; individual credits are in the changelog.

🔒 Security

  • Two cross-tenant backup vulnerabilities (IDOR) fixed. One let any authenticated panel user cancel and delete another tenant’s running backups; the other let any user view, delete or restore another tenant’s incremental-backup snapshots. Both endpoints are now strictly ownership-scoped. These were publicly reported, so upgrading promptly is recommended — especially on servers with more than one panel user.
  • Hardened command and cron handling, and fixed command-injection, SQL-injection, path-traversal and privilege-escalation issues across several endpoints.
  • Added authentication to previously-open git-webhook, AWS-backup and AI Scanner endpoints, strengthened install-time password generation, and the 2FA secret now rotates when two-factor is disabled.

🔐 SSL

  • Renewals now actually apply. The renewed certificate is copied to the served location and LiteSpeed is reloaded, and acme.sh auto-renewals self-apply — fixing sites silently stuck on an old or expiring certificate.
  • Manual “Issue SSL” now forces a real reissue instead of silently doing nothing, and certificate files with trailing junk data no longer break the SSL status display.

💾 Backups & restore

  • Restored and migrated sites are correctly re-owned by the domain user — this fixes WordPress asking for FTP credentials after a restore.
  • Website backups now fail loudly instead of silently producing an archive with no database when the database export fails.

⬆️ Upgrade & install

  • The upgrade script no longer mistakes a healthy install for a corrupt one (which could trigger a destructive recovery re-clone).
  • Upgrade downloads are validated before running, with clean handling of GitHub rate limits.
  • PHP 8.5 no longer crashes the subdomain list, and OWASP CRS installs from the correct URL.

🌐 Domain aliases

  • Alias creation, listing, SSL issuance and deletion now work end-to-end, and orphaned aliases can be cleaned up.

⚙️ Web-server stack

  • Updated CyberPanel-OLS stack: OpenLiteSpeed core 2.5.1, cyberpanel_ols module 2.7.5, mod_security 2.5.1. This resolves the 4xx segfault that caused random Cloudflare 520 errors on affected servers, and all stack binaries are now verified against pinned SHA256 checksums with automatic rollback.

How to upgrade

In your panel go to Version Management → Upgrade, or follow the upgrade guide. The upgrade takes about a minute — snapshot your server first. If you use CyberPanel Cloud, your servers are already patched.

Full changelog: cyberpanel.net/KnowledgeBase/home/change-logs

Issues fixed in this release: #1847, #1835, #1829, #1828, #1823, #1738, #1726, #1720, #1715, #1676, #1814, #1816, #1813, #1811, #1808, #1806, #1804, #1800.

Editorial Team

Written by Editorial Team

The CyberPanel editorial team, under the guidance of Usman Nasir, is composed of seasoned WordPress specialists boasting a decade of expertise in WordPress, Web Hosting, eCommerce, SEO, and Marketing. Since its establishment in 2017, CyberPanel has emerged as the leading free WordPress resource hub in the industry, earning acclaim as the go-to "Wikipedia for WordPress."

Leave a Reply

Your email address will not be published. Required fields are marked *

SIMPLIFY SETUP, MAXIMIZE EFFICIENCY!
Setting up CyberPanel is a breeze. We’ll handle the installation so you can concentrate on your website. Start now for a secure, stable, and blazing-fast performance!
Chat with us on WhatsApp