CVE-2026-88895

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

Scoring

Severity
HIGH
CVSS base score
8.6
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CWE
CWE-287
Published
2026-09-10
Last modified
2026-09-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs