Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84715

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Sep 02, 2026
Vendor unknown

Description

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

References