PT-2026-42014 · Ctrlpanel · Ctrlpanel
CVE-2026-34233
·
Published
2026-05-19
·
Updated
2026-05-20
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CtrlPanel versions prior to 1.2.0
Description
Multiple admin controllers expose DataTable endpoints that lack authorization checks. This allows any authenticated user, regardless of their assigned role, to access sensitive administrative data via GET requests. Although these routes use the '/admin/' prefix, the associated middleware fails to enforce admin-level permissions on the
datatable() functions. This can lead to the exposure of user personally identifiable information (PII), payment and transaction records, active voucher and coupon codes, role and permission structures, server ownership mappings, and support ticket contents.Recommendations
Update to version 1.2.0.
Exploit
Fix
Missing Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ctrlpanel