VYPR

Panel

by Pelican

CVEs (1)

  • CVE-2026-92762HigSep 16, 2026
    risk 0.57cvss 8.8epss

    Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify…