← Vulnerability feed

Vulnerability record · CVE-2023-3266 · published 14 August 2023

CVE-2023-3266: Cyberpower powerpanel server vulnerability

Cyberpower · Powerpanel Server

A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator by selecting LDAP authentication from a hidden HTML combo box. Successful exploitation of this vulnerability also requires the attacker to know at least one username on the device, but any password will authenticate successfully.

9.8 CVSS 3.1 Critical EPSS 0.88% · top 42.5% CWE-358 · CWE-358
9.8CVSS 3.1 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator by selecting LDAP authentication from a hidden HTML combo box. Successful exploitation of this vulnerability also requires the attacker to know at least one username on the device, but any password will authenticate successfully.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-3266 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3264Cyberpower powerpanel server hard-coded credentials vulnerabilityThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres…EPSS 0.47%9.8CVE-2023-3265Cyberpower powerpanel server vulnerabilityAn authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to…EPSS 1.6%8.8CVE-2023-3267Cyberpower powerpanel server os command injection vulnerabilityWhen adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without…EPSS 1.8%8.8CVE-2023-3260Cyberpower powerpanel server os command injection vulnerabilityThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An au…EPSS 1.3%7.2CVE-2023-3261Cyberpower powerpanel server memory buffer overflow vulnerabilityThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Suc…EPSS 0.78%8.8CVE-2024-7965Google Chrome V8 inappropriate implementation allows heap corruptionGoogle Chrome before 128.0.6613.84 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. The flaw is…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2023-3266), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.