{"id":"CVE-2026-88895","title":"CyberPanel before 3.0.5 Authentication Bypass via API","summary":"CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-287"],"vendor":"usmannasir","product":"cyberpanel","affected":["cyberpanel < 3.0.5"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T19:22:41.771489Z"},"published":"2026-09-10","updated":"2026-09-11","sourceUpdated":"2026-09-11T19:22:51.358Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-88895","references":[{"url":"https://github.com/usmannasir/cyberpanel/security/advisories/GHSA-h2f7-38ww-5pwc","label":"GitHub Security Advisory (GHSA-h2f7-38ww-5pwc)"},{"url":"https://www.vulncheck.com/advisories/cyberpanel-before-3.0.5-authentication-bypass-via-api","label":"VulnCheck Advisory: CyberPanel before 3.0.5 Authentication Bypass via API"}],"tags":["cve.org"],"epss":0.00435,"epssPercentile":0.37128,"ingestedAt":"2026-09-14T00:35:28.533Z","slug":"CVE-2026-88895","body":"## Overview\n\nCyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.\n\n## Affected\n\n- `cyberpanel < 3.0.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}