OS Command Injection in Hestia Control Panel - #VU140563
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to improper neutralization of special elements used in an os command in the Restic incremental-restore scheduler and backup queue processing when scheduling a restore operation with crafted parameters. A remote user can send a specially crafted request to execute arbitrary commands as root.
Exploitation requires a valid authenticated panel session and the injected command runs when the scheduled backup queue job is processed, normally within 5 minutes.