8.3
CVE-2026-12196
- EPSS 0.26%
- Veröffentlicht 04.07.2026 12:16:53
- Zuletzt bearbeitet 06.07.2026 19:43:54
- CVE-Watchlists
- Unerledigt
HestiaCP Admin Takeover
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerhestiacp
≫
Produkt
hestiacp
Default Statusunaffected
Version
0
Version <
8be23943c7e3231f66d226ca931c76f93be98412
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.169 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a | 8.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://github.com/hestiacp/hestiacp/pull/5440
https://projectblack.io/blog/hestiacp-admin-takeover-rce/