Vulnerability record · CVE-2023-35885 · published 20 June 2023
CVE-2023-35885: CloudPanel file-manager cookie authentication bypass
Mgt Commerce · Cloudpanel
CloudPanel 2 before 2.3.1 relies on file-manager cookies without validating them, so authentication can be bypassed. The flaw is remotely reachable with no credentials or user interaction, and public exploit code exists, making it a serious risk for exposed CloudPanel instances.
Description
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with public exploit code and very high EPSS probability.
What it is
CloudPanel 2 before 2.3.1 relies on file-manager cookies without validating them, so authentication can be bypassed. The flaw is remotely reachable with no credentials or user interaction, and public exploit code exists, making it a serious risk for exposed CloudPanel instances.
Impact
An unauthenticated attacker can reach the file manager and gain high confidentiality, integrity and availability impact, effectively taking control of files and the hosting environment.
Attack surface
Reachable over the network via the CloudPanel web interface; the CVSS vector shows no privileges required and no user interaction. No pre-existing session or valid credentials are needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.74888 (99.5th percentile) and multiple references are tagged Exploit, indicating public exploit code is available.
What to do
- Upgrade CloudPanel to 2.3.1 or later immediately.
- Restrict access to the CloudPanel management interface to trusted IPs or a VPN.
- Rotate any credentials, API keys or secrets stored on affected hosts.
- Review file-manager and admin logs for unauthorized access before patching.
- Monitor vendor changelog and advisories for follow-up fixes.
Detection
- Alert on file-manager requests lacking a validated session or with anomalous cookie values.
- Monitor for unexpected file writes, uploads or permission changes in CloudPanel-managed directories.
- Baseline and alert on new or unusual source IPs reaching the CloudPanel admin interface.
- Correlate CloudPanel access logs with process execution on the host for post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-35885 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-35885), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.