๐Ÿ” CVE Alert

CVE-2026-92762

HIGH 8.8

Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and variables to execute arbitrary commands in the container.

CWE CWE-862
Vendor pelican
Product panel
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for pelican panel

Be the first to know when new high vulnerabilities affecting pelican panel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

pelican / panel
0 < 1.0.0-beta35

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pelican/panel/security/advisories/GHSA-4x28-f89q-2276 github.com: https://github.com/pelican/panel/blob/fab5da496f7d837574b404e34dc42764a1d6b2c3/app/Filament/Server/Pages/Startup.php#L52-L77 github.com: https://github.com/pelican/panel vulncheck.com: https://www.vulncheck.com/advisories/pelican-panel-before-1.0.0-beta35-authorization-bypass-via-startup

Credits

George Chen