CVE-2026-88895 Details
Description
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
A vulnerability exists in CyberPanel versions through 3.0.4 that allows for two-factor authentication (2FA) to be bypassed on API endpoints. The issue arises because the software accepts password-derived API tokens without enforcing the user's TOTP requirement. As a result, an attacker who gains access to an administrator's password can derive an API token and perform administrative actions or create authenticated sessions without the need for the second authentication factor.
Users can upgrade to CyberPanel version 3.0.5 or later, where this vulnerability has been patched. The update enforces two-factor authentication on all affected API authentication paths and replaces password-derived tokens with high-entropy random credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CyberPanel | <= 3.0.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | [email protected] |
Volerion