Executive brief
ArchitectPanel is a web-based administrative control panel used to manage FuyaWeb Internet services and infrastructure. An execution-after-redirect (EAR) vulnerability allows attackers to bypass authentication and gain unauthorized administrative access, potentially enabling full system compromise and unauthorized configuration changes.
Technical details
The vulnerability is an execution-after-redirect (EAR) flaw in the ArchitectPanel Web Admin Panel that permits authentication bypass. The attack leverages improper redirect handling to allow an unauthenticated attacker to execute administrative actions without valid credentials. The exact attack vector and vulnerable code path are not detailed in the available references, but the network-accessible web interface is the attack surface. An attacker can bypass login controls to gain full administrative privileges. Patches may be available; users should update to versions after 28072026.
Affected products
- FuyaWeb ArchitectPanel through 28072026
Timeline
- 2026-08-21: disclosed