CVE-2026-84715 affects FeatherPanel versions prior to 1.3.7.10, where the SubuserController updateSubuser handler fails to properly validate permissions. Authenticated subusers with minimal privileges can exploit this flaw by sending crafted requests to modify their own permission records. This privilege escalation vulnerability allows attackers to grant themselves full server control. Successful exploitation can lead to unauthorized access to sensitive data, server backups, and server configuration settings. The vulnerability has been patched in FeatherPanel version 1.3.7.10. A fix was committed to the repository and a new release was published. Users are strongly advised to upgrade to the patched version immediately. The issue is tracked by VulnCheck as a privilege escalation advisory.