CVE-2023-3267: Cyberpower Powerpanel Server

High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

Affected products

  • Cyberpower Powerpanel Server: before 2.6.9 (fixed in 2.6.9)

Published 2023-08-14. Last modified 2026-06-17.