Incorrect authorization in Hestia Control Panel - #VU150160

 

Incorrect authorization in Hestia Control Panel - #VU150160

Published: September 16, 2026


Vulnerability identifier: #VU150160
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to retain administrative capabilities after demotion.

The vulnerability exists due to improper authorization based on a stale session role in redirect-only administrative handlers when using a pre-demotion panel session after a role change. A remote privileged user can send requests to the affected handlers to retain administrative capabilities after demotion.

The affected handlers include user deletion, user suspension, bulk user operations, and service restart operations.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.10.5

External References

Related Security Bulletins