Privilege Escalation in FeatherPanel Product by MythicalLTD
CVE-2026-84715
8.7HIGH
What is CVE-2026-84715?
Versions of FeatherPanel prior to 1.3.7.10 have a security flaw in the SubuserController's updateSubuser handler. This flaw allows authenticated subusers with limited permissions to issue crafted requests that improperly modify their own permission levels. As a result, these subusers can elevate their privileges, potentially gaining full control over server functions which could lead to unauthorized access to sensitive information, backups, and server configurations. This vulnerability emphasizes the necessity for effective permission validation to prevent malicious activity.
Affected Version(s)
FeatherPanel 0 < 1.3.7.10
