CVE-2026-12196: HestiaCP Admin Takeover
HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12196?
The severity of CVE-2026-12196 is high, rated at 8.3 on the CVSS scale.
How do I fix CVE-2026-12196?
To fix CVE-2026-12196, ensure that access controls for the cronjob feature in HestiaCP are properly configured to restrict low privilege users from modifying scripts.
What are the potential impacts of CVE-2026-12196?
The potential impacts of CVE-2026-12196 include unauthorized execution of scripts and administrative takeover, compromising the HestiaCP application and server.
Which software is affected by CVE-2026-12196?
CVE-2026-12196 affects the HestiaCP panel.
Who is vulnerable to CVE-2026-12196?
Low privilege users with access to modify the panel cronjob feature in HestiaCP are vulnerable to CVE-2026-12196.