Use of Less Trusted Source in Hestia Control Panel - #VU140560
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass IP-based access restrictions and disclose sensitive information.
The vulnerability exists due to use of a less trusted source in the login handler and IP handling logic when processing the `CF-Connecting-IP` header from client requests. A remote attacker can send a specially crafted request with a spoofed `CF-Connecting-IP` header to bypass IP-based access restrictions and disclose sensitive information.
The issue can bypass fail2ban brute-force protections and poison authentication audit logs by recording the spoofed address instead of the real client IP.