Code Injection in Hestia Control Panel - #VU140553

 

Code Injection in Hestia Control Panel - #VU140553

Published: July 30, 2026


Vulnerability identifier: #VU140553
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands as root.

The vulnerability exists due to improper control of code generation in v-search-user-object when parsing poisoned web.conf path fields with eval. A remote user can store a crafted path value in CUSTOM_DOCROOT, CUSTOM_PHPROOT, or FTP_PATH and trigger the panel Search feature to execute arbitrary commands as root.

The issue is reachable from a low-privileged panel account through the Search functionality, and no user interaction beyond the attacker's own actions is required.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.9.7

External References

Related Security Bulletins