CVE-2026-12196

Source
https://cve.org/CVERecord?id=CVE-2026-12196
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12196.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-12196
Published
2026-07-04T12:05:19Z
Modified
2026-10-08T02:50:38Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
HestiaCP Admin Takeover
Details

HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.

Database specific
{
    "cna_assigner": "PRJBLK",
    "cwe_ids": [
        "CWE-287"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12196.json"
}
References

Affected packages

Git / github.com/hestiacp/hestiacp

Affected ranges

Type
GIT
Repo
https://github.com/hestiacp/hestiacp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.9.8-28
1.*
1.0.1
1.00.0-190618
1.2.0
1.4.0
1.4.1
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.7.0
1.8.0
1.9.0
1.9.1
1.9.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12196.json"