Privilege Escalation in FeatherPanel Product by MythicalLTD
CVE-2026-84715

8.7HIGH

Key Information:

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84715?

Versions of FeatherPanel prior to 1.3.7.10 have a security flaw in the SubuserController's updateSubuser handler. This flaw allows authenticated subusers with limited permissions to issue crafted requests that improperly modify their own permission levels. As a result, these subusers can elevate their privileges, potentially gaining full control over server functions which could lead to unauthorized access to sensitive information, backups, and server configurations. This vulnerability emphasizes the necessity for effective permission validation to prevent malicious activity.

Affected Version(s)

FeatherPanel 0 < 1.3.7.10

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdurakhmon Kodirov
.