Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.3
CVE-2026-12196: HestiaCP Admin Passwordless Access
CVE-2026-12196
CVE-2026-12196
Summary
A security issue in HestiaCP allows low-privilege users to gain full control over the web server and take over administrator accounts. This could lead to unauthorized access and changes to the system. To fix this, update HestiaCP to the latest version and ensure all users have proper access controls in place.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| hestiacp | hestiacp | < 8be23943c7e3231f66d226ca931c76f93be98412 |
Original title
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordles...
Original description
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.
Vulnerability type
CWE-287
Improper Authentication
Published: 4 Jul 2026 · Updated: 20 Jul 2026 · First seen: 4 Jul 2026