CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 14:17
Updated : 2026-09-11 20:19
NVD link : CVE-2026-88895
Mitre link : CVE-2026-88895
CVE.ORG link : CVE-2026-88895
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
