CVE-2023-3267: Cyberpower Powerpanel Server
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.
Affected products
- Cyberpower Powerpanel Server: before 2.6.9 (fixed in 2.6.9)
Published 2023-08-14. Last modified 2026-06-17.