Executive brief
FeatherPanel is a hosting control panel that manages server access and permissions for multiple users. A flaw in the SubuserController allows authenticated subusers (lower-privilege accounts) to modify their own permissions without proper validation, potentially escalating themselves to full server administrator. An attacker could gain unauthorized access to sensitive data, server backups, and configuration settings.
Technical details
The vulnerability is a privilege escalation flaw in the SubuserController's updateSubuser handler that fails to validate permission changes before applying them. Authenticated subusers can send a crafted request to the handler to grant themselves elevated permissions, bypassing authorization checks. The attack requires authentication as a subuser but allows escalation from minimal permissions to full server control. An authenticated attacker can access sensitive data, backups, and server configuration. The vulnerability is fixed in FeatherPanel version 1.3.7.10 and later.
Affected products
- MythicalLTD FeatherPanel before 1.3.7.10
Timeline
- 2026-09-02: disclosed