๐Ÿ” CVE Alert

CVE-2026-84715

HIGH 8.8

FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Update

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

CWE CWE-862
Vendor mythicalltd
Product featherpanel
Published Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for mythicalltd featherpanel

Be the first to know when new high vulnerabilities affecting mythicalltd featherpanel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

MythicalLTD / FeatherPanel
0 < 1.3.7.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MythicalLTD/FeatherPanel/commit/06ef8dcac471201748516ca743694159cb846a9d github.com: https://github.com/MythicalLTD/FeatherPanel/releases/tag/v1.3.7.10 github.com: https://github.com/MythicalLTD/FeatherPanel/blob/376b003aa9685b74153d239d2b3f64a752cdc0f0/backend/app/Controllers/User/Server/SubuserController.php#L454 github.com: https://github.com/MythicalLTD/FeatherPanel/blob/376b003aa9685b74153d239d2b3f64a752cdc0f0/backend/app/Helpers/ServerGateway.php github.com: https://github.com/MythicalLTD/FeatherPanel vulncheck.com: https://www.vulncheck.com/advisories/featherpanel-before-1.3.7.10-privilege-escalation-via-subuser-permission-update

Credits

๐Ÿ” Abdurakhmon Kodirov