Use of Less Trusted Source in Hestia Control Panel - #VU140560

 

Use of Less Trusted Source in Hestia Control Panel - #VU140560

Published: July 30, 2026


Vulnerability identifier: #VU140560
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-348
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass IP-based access restrictions and disclose sensitive information.

The vulnerability exists due to use of a less trusted source in the login handler and IP handling logic when processing the `CF-Connecting-IP` header from client requests. A remote attacker can send a specially crafted request with a spoofed `CF-Connecting-IP` header to bypass IP-based access restrictions and disclose sensitive information.

The issue can bypass fail2ban brute-force protections and poison authentication audit logs by recording the spoofed address instead of the real client IP.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.9.4

External References

Related Security Bulletins