Executive brief
CyberPanel is a web hosting control panel used by administrators to manage servers and hosting accounts. This vulnerability allows an attacker who has obtained an administrator's password to bypass the two-factor authentication (TOTP) protection on API endpoints, enabling them to perform administrative operations and create authenticated sessions without the second factor. An attacker exploiting this could gain full control of hosted environments, compromise customer data, and disrupt services.
Technical details
CyberPanel 3.0.4 and earlier accepts password-derived API tokens and account passwords on the standard API, cloud API router, and cloud session handoff without enforcing TOTP requirements. The vulnerability is an improper authentication issue (CWE-287) where the API authentication paths fail to validate the second factor after primary credential validation. An attacker who obtains an administrator's password can derive the API token and use it to perform administrative operations or create a panel session without supplying the TOTP code. The vulnerability requires the attacker to first obtain the admin password (high privilege requirement) but has a network-based attack vector. The fix in version 3.0.5 enforces TOTP after primary credential validation on all affected API endpoints, replaces password-derived tokens with random credentials, and prevents session handoff without current TOTP codes.
Affected products
- CyberPanel CyberPanel before 3.0.5
Timeline
- 2026-09-10: disclosed
- 2026-08-26: advisory: GitHub security advisory GHSA-h2f7-38ww-5pwc published
- 2026-09-10: patched: Version 3.0.5 released with fix