Not Failing Securely ('Failing Open') in Hestia Control Panel - #VU150159

 

Not Failing Securely ('Failing Open') in Hestia Control Panel - #VU150159

Published: September 16, 2026


Vulnerability identifier: #VU150159
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-636
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to failure to terminate control flow after a redirect in the top_panel() function in web/inc/main.php when handling requests from suspended users with active sessions. A remote user can request the user-management page to disclose sensitive information.

The response body can contain usernames, email addresses, packages, disk and bandwidth quotas, and suspension status for all accounts.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.10.5

External References

Related Security Bulletins