CVE-2023-3265: Cyberpower Powerpanel Server
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.
Affected products
- Cyberpower Powerpanel Server: before 2.6.9 (fixed in 2.6.9)
Published 2023-08-14. Last modified 2026-06-17.