CVE-2026-88895 UNKNOWN

CVE-2026-88895

Published: 2026-09-10

Description

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…