Not Failing Securely ('Failing Open') in Hestia Control Panel - #VU150159
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to failure to terminate control flow after a redirect in the top_panel() function in web/inc/main.php when handling requests from suspended users with active sessions. A remote user can request the user-management page to disclose sensitive information.
The response body can contain usernames, email addresses, packages, disk and bandwidth quotas, and suspension status for all accounts.