Junglewise Threat Intelligence

CVE-2026-12195: myVesta OS command injection in FTP user deletion

CVE-2026-12195 · Severity: info · CVSS 8.5 · Published 2026-07-04

Executive brief

myVesta, a hosting control panel, contains a security flaw that allows users with low-level access to execute unauthorized commands on the server. By manipulating a specific setting when deleting FTP accounts, an attacker can gain the same high-level permissions as the system administrator. This could lead to a complete takeover of the hosting platform, potentially compromising all hosted websites and customer data.

Technical details

An OS command injection vulnerability (CWE-78) exists in myVesta due to improper neutralization of special elements in the 'v_ftp_user' parameter. The vulnerability occurs within the FTP user deletion logic in 'web/edit/web/index.php', where user-supplied input is concatenated into an 'exec()' call without sufficient shell escaping. An authenticated attacker with low privileges can inject shell commands that execute with the privileges of the admin user. The issue is resolved by applying 'escapeshellarg()' to the affected parameter, as seen in the vendor's patch (commit 95d7e43).

Affected products

  • myVesta vesta versions prior to commit 95d7e43bf286d6881ca753dac93cb42d98cc7422

Timeline

  • 2026-06-28: disclosed: Vulnerability identified during AI benchmarking research by Project Black.
  • 2026-07-04: advisory: CVE-2026-12195 published.
  • 2026-07-04: patched: Fix committed to the myVesta repository.

References