Code Injection in Hestia Control Panel - #VU140553
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to improper control of code generation in v-search-user-object when parsing poisoned web.conf path fields with eval. A remote user can store a crafted path value in CUSTOM_DOCROOT, CUSTOM_PHPROOT, or FTP_PATH and trigger the panel Search feature to execute arbitrary commands as root.
The issue is reachable from a low-privileged panel account through the Search functionality, and no user interaction beyond the attacker's own actions is required.