Impact
Pelican Panel versions prior to 1.0.0-beta35 contain an authorization bypass that allows a user with startup.read permission to alter startup configuration through Livewire state updates. By manipulating afterStateUpdated callbacks, the attacker can modify startup commands, Docker images, and environment variables, effectively executing arbitrary commands inside the container. This flaw arises from disabled form controls instead of server‑side checks, mapping directly to CWE‑862.
Affected Systems
Affected systems include the Pelican Panel application for all releases before version 1.0.0-beta35. Administrators should verify whether their environment hosts any of these prior versions. The vulnerability is present in every iteration until the fix in 1.0.0-beta35 is applied.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Once an attacker has, or gains, a user role with startup.read privileges, they can exploit the flaw remotely via the web interface by sending crafted Livewire requests. Because the bug bypasses server‑side authorization, any user who can read startup data is a potential vector for arbitrary command execution within the container.
OpenCVE Enrichment