Description
Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass.

This issue affects ArchitectPanel Web Admin Panel: through 28072026.
Published: 2026-08-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Execution After Redirect flaw that lets attackers bypass authentication in FuyaWeb's ArchitectPanel Web Admin Panel. By manipulating the redirect logic, an attacker can gain unauthorized access to administrative functions, with the potential to modify configuration, exfiltrate data, or take control of the service. The defect is a logic error classified as CWE‑698, where the system incorrectly trusts a redirected request. Due to the lack of proper authentication regeneration after the redirect, the flaw results in a complete loss of access control. The CVSS score of 7.5 indicates a high severity, while the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Nonetheless, the flaw can be triggered over the network through crafted web requests, making it a real threat to any installed instance until a patch or workaround is applied.

Affected Systems

Affected systems are installations of the FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel with versions up to and including Build 28072026; deployment of this component in any environment before this build would be susceptible to authentication bypass. The product is primarily used for web‑based management of network and application resources, and the flaw affects all users who rely on the standard login workflow. Users running this version must verify their deployment and plan remediation, as every instance of the panel remains exposed until remediated.

Risk and Exploitability

The CVSS score of 7.5 points to a high impact, and while the EPSS score is not available, the potential for exploitation is significant because the flaw is exploitable via a straightforward HTTP redirect manipulation. Attackers could reach the panel remotely, send a specially crafted request that triggers the redirect, and obtain authenticated access without providing valid credentials. Because the flaw is not yet in the KEV catalog, there is no confirmed exploit, but the logical nature of the weakness suggests that exploitation does not require advanced techniques, making the vulnerability a priority for swift mitigation.

Generated by OpenCVE AI on August 21, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade FuyaWeb ArchitectPanel to a version newer than 28072026, which addresses the redirect logic flaw.
  • If a patch is not yet available, disable or restrict execution after redirects in the panel’s configuration, limiting redirects to trusted origins only.
  • Enable detailed logging of authentication attempts and monitor for abnormal redirect patterns to detect attempted bypasses, and enforce network controls to block unauthorized remote access.

Generated by OpenCVE AI on August 21, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Fuyaweb
Fuyaweb architectpanel Web Admin Panel
Vendors & Products Fuyaweb
Fuyaweb architectpanel Web Admin Panel

Fri, 21 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.
Title Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
Weaknesses CWE-698
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Fuyaweb Architectpanel Web Admin Panel
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-21T20:08:37.537Z

Reserved: 2026-07-20T17:41:28.040Z

Link: CVE-2026-16323

cve-icon Vulnrichment

Updated: 2026-08-21T20:06:17.984Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T08:16:42.667

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-16323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:08:07Z

Weaknesses
  • CWE-698

    Execution After Redirect (EAR)