CPE
Pelican Panel versions before 1.0.0-beta35 fail to enforce server-side write permissions, allowing attackers with read-only access to achieve arbitrary command execution via manipulated Livewire state updates.