Skip to content
Threat Feed
high advisory

CyberPanel Authentication Bypass via API

CyberPanel versions prior to 3.0.5 contain an authentication bypass vulnerability where two-factor authentication is not enforced on API endpoints, allowing credential-derived token misuse.

CVE search metadata

CVE search record: CVE-2026-88895. Severity: high. CVSS: 7.2. KEV: no. Product: CyberPanel (< 3.0.5). Brief: CyberPanel Authentication Bypass via API. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cyberpanel-auth-bypass/

CyberPanel versions prior to 3.0.5 are vulnerable to an authentication bypass due to the failure to enforce two-factor authentication (TOTP) on API endpoints. An attacker who obtains an administrator's password can derive API tokens, effectively bypassing the second-factor requirement to execute administrative operations or establish unauthorized sessions. This vulnerability impacts the control plane of the CyberPanel environment, potentially allowing attackers to gain full administrative access to hosted web services and panel configurations. Defenders should prioritize patching to version 3.0.5 or later to restore TOTP integrity for all API-based authentication attempts.

Impact

Successful exploitation allows an attacker to bypass MFA protections and gain administrative access to CyberPanel. This leads to full administrative control over the panel, enabling configuration changes, service disruption, and access to all managed web content and databases.

Recommendation

  1. Patch all CyberPanel instances to version 3.0.5 or later immediately to enforce TOTP on API endpoints.
  2. Implement monitoring for anomalous API calls originating from administrative accounts that lack corresponding multi-factor authentication events in the audit logs.
  3. Audit current administrative sessions for signs of unauthorized access, specifically looking for token-based authentication patterns that deviate from standard browser-based login workflows.

Immediate actions

Upgrade CyberPanel to 3.0.5 or later

IT Operations 24h

Mitigations

Upgrade to version 3.0.5

immediate IT Operations

CVE-2026-88895