CVE-2023-35885: Mgt-Commerce Cloudpanel

Critical severity, CVSS 9.8. EPSS: 74.9% chance of exploitation in the next 30 days.

CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

Affected products

  • Mgt-Commerce Cloudpanel: from 2.0.0, before 2.3.1 (fixed in 2.3.1)

Published 2023-06-20. Last modified 2026-06-17.