Executive brief
CPA-Manager-Plus is a self-hosted management panel for API proxy and monitoring. A flaw in its HTTP handler allows attackers to bypass authorization checks on certain operations, potentially granting unauthorized access to sensitive resources or functionality. This could enable data exfiltration, configuration tampering, or lateral movement within the managed infrastructure.
Technical details
The vulnerability is an improper authorization issue in the CPAResource function of the HTTP Handler component (located in apps/manager-server/internal/http/controller/proxy/handler.go). The flaw allows attackers to perform unauthorized actions by bypassing authentication/authorization checks. The attack is network-accessible and does not require prior authentication or user interaction. An attacker can remotely exploit this to gain unauthorized access to protected API proxy resources. The issue is resolved in version 1.11.11 via patch 842eec791377ddcbea5cd639bc065eaa4801d656.
Affected products
- seakee CPA-Manager-Plus up to 1.11.10
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Version 1.11.11 resolves the issue