{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-92762/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pelican_panel:pelican_panel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92762"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pelican Panel (\u003c 1.0.0-beta35)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","authorization-bypass","cve-2026-92762"],"_cs_type":"advisory","_cs_vendors":["Pelican Panel"],"content_html":"\u003cp\u003ePelican Panel versions prior to 1.0.0-beta35 contain an authorization bypass vulnerability (CVE-2026-92762) affecting startup configuration management. The application erroneously relies on client-side form controls to restrict write access to startup settings. An attacker possessing only 'startup.read' permissions can exploit this by crafting malicious Livewire state updates. These updates trigger 'afterStateUpdated' callbacks, which bypass intended authorization checks. By invoking these callbacks, the attacker can modify critical server settings, including startup commands, Docker images, and environment variables. This manipulation allows for the injection of malicious payloads that result in arbitrary command execution within the application container. The vulnerability highlights the danger of relying on UI-level restrictions for security-sensitive administrative operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker with limited read-only permissions to gain full control over the container environment managed by Pelican Panel. This enables arbitrary code execution, potential data exfiltration from the container, and lateral movement within the host infrastructure if container isolation is insufficient.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Pelican Panel instances to version 1.0.0-beta35 or later immediately to patch CVE-2026-92762.\u003c/li\u003e\n\u003cli\u003eAudit user permission sets within Pelican Panel to ensure that the 'startup.read' permission is limited to the minimum number of users required.\u003c/li\u003e\n\u003cli\u003eReview and harden Docker container security profiles (e.g., using AppArmor or Seccomp) to limit the impact of potential arbitrary command execution within the container runtime.\u003c/li\u003e\n\u003cli\u003eImplement monitoring on administrative API endpoints related to startup configurations and Livewire state management to detect abnormal update patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:55:27Z","date_published":"2026-09-16T21:55:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pelican-panel-auth-bypass/","summary":"Pelican Panel versions before 1.0.0-beta35 fail to enforce server-side write permissions, allowing attackers with read-only access to achieve arbitrary command execution via manipulated Livewire state updates.","title":"Authorization Bypass in Pelican Panel via Livewire State Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-09-pelican-panel-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-92762","version":"https://jsonfeed.org/version/1.1"}