Officially credited finder
$ verify --cve CVE-2026-16323
CVE-2026-16323
Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
An execution-after-redirect vulnerability could allow an unauthenticated remote attacker to bypass authentication.
Public record summary
- Researcher credit
- Basri Akkaya — finder
- Vendor
- FuyaWeb Internet and Informatics Services
- Affected product
- ArchitectPanel Web Admin Panel
- Severity
- HIGH · CVSS 7.5
- Published
- CVE
- CVE-2026-16323
Technical classification
CWE-698Execution After Redirect (EAR)MITRE CWE definition (opens in a new tab)CAPEC-115Authentication BypassMITRE CAPEC definition (opens in a new tab)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Authoritative sources
The facts and researcher credit on this page are based on the published CVE record and the government advisory.
Responsible disclosure note
This page summarizes public information only. It does not publish private report material, credentials, or undisclosed exploitation details.