CVE-2026-84715

Source
https://cve.org/CVERecord?id=CVE-2026-84715
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84715.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84715
Published
2026-09-02T01:18:16Z
Modified
2026-09-12T03:30:16Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Update
Details

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84715.json"
}
References

Affected packages

Git / github.com/mythicalltd/featherpanel

Affected ranges

Type
GIT
Repo
https://github.com/mythicalltd/featherpanel
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.3.7.10"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.1-canary
v0.*
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.4.1
v1.0.5
v1.0.6
v1.1.0
v1.1.0-hotfix
v1.1.1
v1.1.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.3.6.1
v1.3.6.2
v1.3.6.3
v1.3.6.4
v1.3.6.5
v1.3.6.6
v1.3.7
v1.3.7.1
v1.3.7.2
v1.3.7.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84715.json"