{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acyberpanelcyberpanel/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-88895"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CyberPanel (\u003c 3.0.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authentication-bypass","cve-2026-88895"],"_cs_type":"advisory","_cs_vendors":["CyberPanel"],"content_html":"\u003cp\u003eCyberPanel versions prior to 3.0.5 are vulnerable to an authentication bypass due to the failure to enforce two-factor authentication (TOTP) on API endpoints. An attacker who obtains an administrator's password can derive API tokens, effectively bypassing the second-factor requirement to execute administrative operations or establish unauthorized sessions. This vulnerability impacts the control plane of the CyberPanel environment, potentially allowing attackers to gain full administrative access to hosted web services and panel configurations. Defenders should prioritize patching to version 3.0.5 or later to restore TOTP integrity for all API-based authentication attempts.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to bypass MFA protections and gain administrative access to CyberPanel. This leads to full administrative control over the panel, enabling configuration changes, service disruption, and access to all managed web content and databases.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch all CyberPanel instances to version 3.0.5 or later immediately to enforce TOTP on API endpoints.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for anomalous API calls originating from administrative accounts that lack corresponding multi-factor authentication events in the audit logs.\u003c/li\u003e\n\u003cli\u003eAudit current administrative sessions for signs of unauthorized access, specifically looking for token-based authentication patterns that deviate from standard browser-based login workflows.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T15:16:32Z","date_published":"2026-09-10T15:16:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cyberpanel-auth-bypass/","summary":"CyberPanel versions prior to 3.0.5 contain an authentication bypass vulnerability where two-factor authentication is not enforced on API endpoints, allowing credential-derived token misuse.","title":"CyberPanel Authentication Bypass via API","url":"https://feed.craftedsignal.io/briefs/2026-09-cyberpanel-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}