CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor. | |
| Title | CyberPanel before 3.0.5 Authentication Bypass via API | |
| First Time appeared |
Cyberpanel
Cyberpanel cyberpanel |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cyberpanel
Cyberpanel cyberpanel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-10T13:05:42.380Z
Reserved: 2026-09-10T11:28:50.297Z
Link: CVE-2026-88895
No data.
Status : Deferred
Published: 2026-09-10T14:17:18.907
Modified: 2026-09-10T15:13:07.090
Link: CVE-2026-88895
No data.
OpenCVE Enrichment
Updated: 2026-09-10T15:00:15Z
Weaknesses