Interpretation Conflict in Hestia Control Panel - #VU140561

 

Interpretation Conflict in Hestia Control Panel - #VU140561

Published: July 30, 2026


Vulnerability identifier: #VU140561
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-436
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to interpretation conflict in the web terminal session parser when processing shared session files containing attacker-controlled header data. A remote attacker can send a specially crafted X-Forwarded-For header to execute arbitrary code.

Exploitation is possible only when the web terminal is enabled.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.9.6

External References

Related Security Bulletins