<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CyberPanel (&lt; 3.0.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cyberpanel--3.0.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 15:16:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cyberpanel--3.0.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CyberPanel Authentication Bypass via API</title><link>https://feed.craftedsignal.io/briefs/2026-09-cyberpanel-auth-bypass/</link><pubDate>Thu, 10 Sep 2026 15:16:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cyberpanel-auth-bypass/</guid><description>CyberPanel versions prior to 3.0.5 contain an authentication bypass vulnerability where two-factor authentication is not enforced on API endpoints, allowing credential-derived token misuse.</description><content:encoded><![CDATA[<p>CyberPanel versions prior to 3.0.5 are vulnerable to an authentication bypass due to the failure to enforce two-factor authentication (TOTP) on API endpoints. An attacker who obtains an administrator's password can derive API tokens, effectively bypassing the second-factor requirement to execute administrative operations or establish unauthorized sessions. This vulnerability impacts the control plane of the CyberPanel environment, potentially allowing attackers to gain full administrative access to hosted web services and panel configurations. Defenders should prioritize patching to version 3.0.5 or later to restore TOTP integrity for all API-based authentication attempts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to bypass MFA protections and gain administrative access to CyberPanel. This leads to full administrative control over the panel, enabling configuration changes, service disruption, and access to all managed web content and databases.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch all CyberPanel instances to version 3.0.5 or later immediately to enforce TOTP on API endpoints.</li>
<li>Implement monitoring for anomalous API calls originating from administrative accounts that lack corresponding multi-factor authentication events in the audit logs.</li>
<li>Audit current administrative sessions for signs of unauthorized access, specifically looking for token-based authentication patterns that deviate from standard browser-based login workflows.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>authentication-bypass</category><category>cve-2026-88895</category></item></channel></rss>