---
id: CVE-2026-88895
title: CyberPanel before 3.0.5 Authentication Bypass via API
summary: >-
  CyberPanel before 3.0.5 fails to enforce two-factor authentication on API
  endpoints, allowing attackers to bypass TOTP requirements using
  password-derived tokens. Attackers who obtain an administrator's password can
  derive API tokens and…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-287
vendor: usmannasir
product: cyberpanel
affected:
  - cyberpanel < 3.0.5
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T19:22:41.771489Z'
published: '2026-09-10'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T19:22:51.358Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-88895'
references:
  - url: >-
      https://github.com/usmannasir/cyberpanel/security/advisories/GHSA-h2f7-38ww-5pwc
    label: GitHub Security Advisory (GHSA-h2f7-38ww-5pwc)
  - url: >-
      https://www.vulncheck.com/advisories/cyberpanel-before-3.0.5-authentication-bypass-via-api
    label: 'VulnCheck Advisory: CyberPanel before 3.0.5 Authentication Bypass via API'
tags:
  - cve.org
epss: 0.00435
epssPercentile: 0.37128
ingestedAt: '2026-09-14T00:35:28.533Z'
---

## Overview

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

## Affected

- `cyberpanel < 3.0.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
