Impact
A flaw in CyberPanel versions prior to 3.0.5 allows administrators who possess a user password to generate API tokens bypassing the two‑factor authentication requirement. By deriving these tokens from the admin password, an attacker can invoke privileged API calls or establish authenticated sessions without providing the second factor. The weakness is a classic authentication bypass described by CWE-287. The result is the ability to perform any administrative operation, silently create users, or otherwise compromise the entire management interface. This attack does not require any user interaction beyond the initial password compromise.
Affected Systems
The vulnerability affects all CyberPanel installations from the vendor usmannasir:cyberpanel where the version is earlier than 3.0.5. No other products or later releases are affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity and confirms that the flaw permits critical manipulation of the system once an attacker gains administrator credentials. EPSS information is not provided, so the probability of exploitation in the wild cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack path requires the attacker to have the administrator’s password; upon obtaining it, they can request token generation on any vulnerable API endpoint, effectively bypassing two‑factor authentication and gaining full control of the platform.
OpenCVE Enrichment