Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88895

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

EPSS

Процентиль: 37%
0.00435
Низкий

7.2 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.2
github
13 дней назад

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

EPSS

Процентиль: 37%
0.00435
Низкий

7.2 High

CVSS3

Дефекты

CWE-287