PatchSiren

pelican CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pelican CVE published 2026-09-16

CVE-2026-92762

Pelican Panel versions before 1.0.0-beta35 have a vulnerability where attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and variables to execute arbitrary commands in the container. This high-severity issue requires immediate attention from defenders responsible for Pelican Panel instances, especially t [truncated]