Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.
File upload security needs strict validation, object storage, edge limits, streaming, malware scanning, safe names and ...