FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-862"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84715.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.3.7.10"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}