Junglewise Threat Intelligence

CVE-2026-84715: MythicalLTD FeatherPanel privilege escalation in SubuserController

CVE-2026-84715 · Severity: high · CVSS 8.8 · Published 2026-09-02

Executive brief

FeatherPanel is a hosting control panel that manages server access and permissions for multiple users. A flaw in the SubuserController allows authenticated subusers (lower-privilege accounts) to modify their own permissions without proper validation, potentially escalating themselves to full server administrator. An attacker could gain unauthorized access to sensitive data, server backups, and configuration settings.

Technical details

The vulnerability is a privilege escalation flaw in the SubuserController's updateSubuser handler that fails to validate permission changes before applying them. Authenticated subusers can send a crafted request to the handler to grant themselves elevated permissions, bypassing authorization checks. The attack requires authentication as a subuser but allows escalation from minimal permissions to full server control. An authenticated attacker can access sensitive data, backups, and server configuration. The vulnerability is fixed in FeatherPanel version 1.3.7.10 and later.

Affected products

  • MythicalLTD FeatherPanel before 1.3.7.10

Timeline

  • 2026-09-02: disclosed

References