Code Injection in Hestia Control Panel - #VU140987

 

Code Injection in Hestia Control Panel - #VU140987

Published: August 5, 2026


Vulnerability identifier: #VU140987
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code as root.

The vulnerability exists due to improper control of code generation in v-update-user-backup-exclusions and source_conf() when processing crafted backup exclusion input. A remote user can send a specially crafted POST request containing newline-separated KEY=VALUE data to execute arbitrary code as root.

No user interaction is required beyond submitting the save request.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.9.9

External References

Related Security Bulletins