Junglewise Threat Intelligence

CVE-2026-12196: HestiaCP broken access control in panel cronjob feature

CVE-2026-12196 · Severity: info · CVSS 8.3 · Published 2026-07-04

Technologies: HestiaCP. Vendors: HestiaCP.

Executive brief

HestiaCP, a popular open-source web server control panel, contains a security flaw in its task scheduling (cron) feature. This vulnerability allows a standard, low-privileged user to modify administrative system tasks that they should not have access to. By exploiting this, an attacker can gain full control over the administrator account and the underlying web server, potentially leading to a complete system takeover and data theft.

Technical details

A broken access control vulnerability (CWE-287/CWE-285) exists in the HestiaCP web panel due to an improperly implemented authorization check in the cron job management component. The check relies on an undefined variable ($ROOT_USER), causing the logic to fail and allowing low-privileged users to modify 'panel cron jobs' that execute as the privileged panel user. Because the panel user has passwordless sudo access to administrative scripts (e.g., v-change-user-password), an authenticated attacker can schedule a task to reset the administrator's password or execute other management commands. The vulnerability is further exacerbated by a lack of CSRF validation on the affected endpoint. A fix was introduced in commit 8be2394.

Affected products

  • HestiaCP HestiaCP Prior to commit 8be23943c7e3231f66d226ca931c76f93be98412

Timeline

  • 2026-06-23: patched: Fix merged into main branch via Pull Request 5440
  • 2026-07-04: disclosed: Public advisory and blog post published
  • 2026-07-04: advisory: NVD entry published

References

Related threats