CVE-2026-12195: OS Command Injection
Published Jul 4, 2026
·Updated
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the vftpuser parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
Affected Software
1 affected component
myVesta
Event History
Jul 4, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12195?
CVE-2026-12195 has a high severity rating of 8.5.
2
How do I fix CVE-2026-12195?
To fix CVE-2026-12195, update myVesta to the latest version where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2026-12195?
CVE-2026-12195 is an authenticated remote code execution vulnerability.
4
Who is affected by CVE-2026-12195?
CVE-2026-12195 affects low privileged users of the myVesta software.
5
What impact does CVE-2026-12195 have?
CVE-2026-12195 can allow attackers to execute arbitrary commands as the admin user.