← Database

CVE-2026-84715

HIGH CVSS: 8.8 Published: 2026-09-02 Modified: 2026-09-02

Description

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

Affected Platforms

Unknown

Weakness Type

CWE-862

References