Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92762— Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup

Quick assessment

Affected
pelican panel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Pelican Panel 1.0.0-beta35 之前版本仅通过禁用的表单控件来强制实施启动时写入权限,而未进行服务器端的授权检查。拥有 startup.read 权限的攻击者可以构造 Livewire 状态更新,以触发 afterStateUpdated 回调函数,并修改启动命令、Docker 镜像和变量,从而在容器内执行任意命令。

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92762

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup
Source: CVE Program / CVE List V5
Vulnerability Description
Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and variables to execute arbitrary commands in the container.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pelican panel 0 ~ 1.0.0-beta35 -

II. Public POCs for CVE-2026-92762

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92762

登录查看更多情报信息。

Other References for CVE-2026-92762 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92762

No comments yet


Leave a comment