CVE-2023-3265: Cyberpower Powerpanel Server

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator with hardcoded default credentials.

Affected products

  • Cyberpower Powerpanel Server: before 2.6.9 (fixed in 2.6.9)

Published 2023-08-14. Last modified 2026-06-17.