OS Command Injection in Hestia Control Panel - #VU140557

 

OS Command Injection in Hestia Control Panel - #VU140557

Published: July 30, 2026


Vulnerability identifier: #VU140557
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands as root.

The vulnerability exists due to improper neutralization of special elements used in an os command in the queue execution mechanism when processing backup and restore parameters across multiple execution contexts. A remote user can send crafted restore parameters that are written into .pipe queue files to execute arbitrary commands as root.

The issue is second-order and is triggered when a root-level cron job executes queued .pipe files through /bin/sh.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.9.5

External References

Related Security Bulletins