Incorrect authorization in Hestia Control Panel - #VU150162

 

Incorrect authorization in Hestia Control Panel - #VU150162

Published: September 16, 2026


Vulnerability identifier: #VU150162
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands in the protected administrator account\'s context.

The vulnerability exists due to incorrect authorization in the cron job creation endpoint when handling cron job creation requests while impersonating the protected administrator account. A remote privileged user can impersonate the protected administrator account and submit a cron job creation request to execute arbitrary commands in the protected administrator account\'s context.


Affected software

Hestia Control Panel

Remediation

Install security update from vendor's website.

Hestia Control Panel - update to 1.10.5

External References

Related Security Bulletins