1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.
History

Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared 1panel
1panel 1panel
Linux
Linux linux
Vendors & Products 1panel
1panel 1panel
Linux
Linux linux

Tue, 09 Dec 2025 02:00:00 +0000

Type Values Removed Values Added
Description 1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable CAPTCHA verification by abusing a client-controlled parameter. Because the server previously trusted this value without proper validation, CAPTCHA protections can be bypassed, enabling automated login attempts and significantly increasing the risk of account takeover (ATO). This issue is fixed in version 2.0.14.
Title 1Panel – CAPTCHA Bypass via Client-Controlled Flag
Weaknesses CWE-290
CWE-602
CWE-807
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-09T01:25:48.140Z

Updated: 2025-12-09T16:03:18.696Z

Reserved: 2025-12-03T15:12:22.978Z

Link: CVE-2025-66507

cve-icon Vulnrichment

Updated: 2025-12-09T14:17:22.158Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:18:19.270

Modified: 2025-12-09T18:36:53.557

Link: CVE-2025-66507

cve-icon Redhat

No data.