Improper Authorization in Hestia Control Panel - #VU140555
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper authorization in the admin panel crontab management endpoint when handling a manual POST request to save panel cronjobs. A remote user can submit a specially crafted request to overwrite or add a panel cronjob to escalate privileges.
The injected panel cronjob can execute Hestia scripts via sudo without a password, allowing takeover of the admin account after the scheduled job runs.