CVE-2020-10786: Critical severity VestaCP Vesta Control Panel vulnerability
Published Apr 21, 2020
·Updated
A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.
Affected Software
1 affected component
VestaCP Vesta Control Panel<=0.9.8-26
Remediation
Patch Available
Event History
Apr 21, 2020
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
Frequently Asked Questions
1
What is CVE-2020-10786?
CVE-2020-10786 is a vulnerability in Vesta Control Panel through 0.9.8-26 that allows any authenticated user to execute arbitrary commands on the system via cron jobs.
2
What is the severity of CVE-2020-10786?
The severity of CVE-2020-10786 is critical with a CVSS score of 8.8.
3
Which software versions are affected by CVE-2020-10786?
Vesta Control Panel versions up to and including 0.9.8-26 are affected by CVE-2020-10786.
4
How can an authenticated user exploit CVE-2020-10786?
An authenticated user can exploit CVE-2020-10786 by executing arbitrary commands on the system through cron jobs.
5
Is there a fix for CVE-2020-10786?
Yes, updating Vesta Control Panel to a version later than 0.9.8-26 fixes CVE-2020-10786.