<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:featherpanel:featherpanel:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afeatherpanelfeatherpanel/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 05:11:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afeatherpanelfeatherpanel/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in FeatherPanel SubuserController</title><link>https://feed.craftedsignal.io/briefs/2026-09-featherpanel-auth-bypass/</link><pubDate>Wed, 02 Sep 2026 05:11:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-featherpanel-auth-bypass/</guid><description>Authenticated subusers can exploit a permission validation failure in FeatherPanel versions before 1.3.7.10 to escalate privileges to full server control.</description><content:encoded><![CDATA[<p>FeatherPanel versions prior to 1.3.7.10 contain a critical authorization vulnerability within the SubuserController updateSubuser handler. This vulnerability arises due to a failure to validate permissions during the update process for subuser accounts. An authenticated attacker possessing a low-privileged subuser account can submit a crafted request to the application to modify their own permission records. By manipulating these records, a subuser can grant themselves elevated administrative privileges, including full server control. This escalation allows the attacker to gain unauthorized access to sensitive server data, configuration files, and backups, effectively compromising the integrity and confidentiality of the hosting environment managed by the panel. This vulnerability is classified as an authorization bypass, allowing privilege escalation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows low-privileged subusers to gain full administrative control over the FeatherPanel installation. This results in unauthorized access to sensitive server-side data, system configurations, and automated backups. Depending on the server deployment, this could lead to total system compromise, exfiltration of customer data, or disruption of hosted services.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all FeatherPanel instances to version 1.3.7.10 or later immediately.</li>
<li>Audit logs for suspicious activity originating from existing subuser accounts, specifically monitoring for frequent or unauthorized modification requests to the SubuserController endpoint.</li>
<li>Review all current subuser privilege levels to identify unauthorized account upgrades that may have occurred prior to patching.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>