Junglewise Threat Intelligence

CVE-2026-16323: FuyaWeb ArchitectPanel authentication bypass via execution after redirect

CVE-2026-16323 · Severity: high · CVSS 7.5 · Published 2026-08-21

Executive brief

ArchitectPanel is a web-based administrative control panel used to manage FuyaWeb Internet services and infrastructure. An execution-after-redirect (EAR) vulnerability allows attackers to bypass authentication and gain unauthorized administrative access, potentially enabling full system compromise and unauthorized configuration changes.

Technical details

The vulnerability is an execution-after-redirect (EAR) flaw in the ArchitectPanel Web Admin Panel that permits authentication bypass. The attack leverages improper redirect handling to allow an unauthenticated attacker to execute administrative actions without valid credentials. The exact attack vector and vulnerable code path are not detailed in the available references, but the network-accessible web interface is the attack surface. An attacker can bypass login controls to gain full administrative privileges. Patches may be available; users should update to versions after 28072026.

Affected products

  • FuyaWeb ArchitectPanel through 28072026

Timeline

  • 2026-08-21: disclosed

References