PT-2026-42014 · Ctrlpanel · Ctrlpanel
Published
2026-05-19
·
Updated
2026-05-20
·
CVE-2026-34233
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CtrlPanel versions prior to 1.2.0
Description
Multiple admin controllers expose DataTable endpoints that lack authorization checks. This allows any authenticated user, regardless of their assigned role, to access sensitive administrative data via GET requests. Although these routes use the '/admin/' prefix, the associated middleware fails to enforce admin-level permissions on the
datatable() functions. This can lead to the exposure of user personally identifiable information (PII), payment and transaction records, active voucher and coupon codes, role and permission structures, server ownership mappings, and support ticket contents.Recommendations
Update to version 1.2.0.
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ctrlpanel