Description
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
Published: 2026-09-10
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass via API
Action: Patch Immediately
AI Analysis

Impact

A flaw in CyberPanel versions prior to 3.0.5 allows administrators who possess a user password to generate API tokens bypassing the two‑factor authentication requirement. By deriving these tokens from the admin password, an attacker can invoke privileged API calls or establish authenticated sessions without providing the second factor. The weakness is a classic authentication bypass described by CWE-287. The result is the ability to perform any administrative operation, silently create users, or otherwise compromise the entire management interface. This attack does not require any user interaction beyond the initial password compromise.

Affected Systems

The vulnerability affects all CyberPanel installations from the vendor usmannasir:cyberpanel where the version is earlier than 3.0.5. No other products or later releases are affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity and confirms that the flaw permits critical manipulation of the system once an attacker gains administrator credentials. EPSS information is not provided, so the probability of exploitation in the wild cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack path requires the attacker to have the administrator’s password; upon obtaining it, they can request token generation on any vulnerable API endpoint, effectively bypassing two‑factor authentication and gaining full control of the platform.

Generated by OpenCVE AI on September 10, 2026 at 14:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply CyberPanel version 3.0.5 or later to remove the authentication bypass flaw.
  • Disable or restrict API endpoints for privileged accounts if possible and enforce strict access controls.
  • Enable or mandate two‑factor authentication for all administrator logins and audit API usage logs for unusual activity.

Generated by OpenCVE AI on September 10, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
Title CyberPanel before 3.0.5 Authentication Bypass via API
First Time appeared Cyberpanel
Cyberpanel cyberpanel
Weaknesses CWE-287
CPEs cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*
Vendors & Products Cyberpanel
Cyberpanel cyberpanel
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cyberpanel Cyberpanel
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T13:05:42.380Z

Reserved: 2026-09-10T11:28:50.297Z

Link: CVE-2026-88895

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:17:18.907

Modified: 2026-09-10T15:13:07.090

Link: CVE-2026-88895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:00:15Z

Weaknesses