CVE-2026-92762
Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and variables to execute arbitrary commands in the container.
| CWE | CWE-862 |
| Vendor | pelican |
| Product | panel |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for pelican panel
Be the first to know when new high vulnerabilities affecting pelican panel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
pelican / panel
0 < 1.0.0-beta35
References
github.com: https://github.com/pelican/panel/security/advisories/GHSA-4x28-f89q-2276 github.com: https://github.com/pelican/panel/blob/fab5da496f7d837574b404e34dc42764a1d6b2c3/app/Filament/Server/Pages/Startup.php#L52-L77 github.com: https://github.com/pelican/panel vulncheck.com: https://www.vulncheck.com/advisories/pelican-panel-before-1.0.0-beta35-authorization-bypass-via-startup
Credits
George Chen