Incorrect authorization in Hestia Control Panel - #VU150162
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands in the protected administrator account\'s context.
The vulnerability exists due to incorrect authorization in the cron job creation endpoint when handling cron job creation requests while impersonating the protected administrator account. A remote privileged user can impersonate the protected administrator account and submit a cron job creation request to execute arbitrary commands in the protected administrator account\'s context.