1Panel CAPTCHA Bypass Vulnerability in Authentication API

Vulnerability

A CAPTCHA verification bypass vulnerability has been identified in 1Panel, an open-source web-based control panel for Linux server management. This vulnerability affects versions through 2.0.13. It allows an unauthenticated attacker to disable CAPTCHA verification by exploiting a client-controlled parameter in the login API. The server's trust in this parameter, without proper validation, enables the bypass of CAPTCHA protections. As a result, automated login attempts can be made, significantly increasing the risk of account takeover.

Impact

Exploitation of this vulnerability allows for unauthorized bypassing of CAPTCHA verification, enabling automated login attempts and increasing the risk of account takeover.

Reproduction

To reproduce this vulnerability, send a request to the /api/login endpoint with the 'ignoreCaptcha' parameter set to true. This will disable the CAPTCHA verification process, allowing for automated login attempts to be made without the usual CAPTCHA challenge.

Remediation

Users can upgrade to 1Panel version 2.0.14 or later, where this vulnerability has been patched.

Added: Dec 9, 2025, 6:33 PM
Updated: Dec 10, 2025, 12:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.7
remediation
7.7
relevance
1.3
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.