Executive brief
HestiaCP, a popular open-source web server control panel, contains a security flaw in its task scheduling (cron) feature. This vulnerability allows a standard, low-privileged user to modify administrative system tasks that they should not have access to. By exploiting this, an attacker can gain full control over the administrator account and the underlying web server, potentially leading to a complete system takeover and data theft.
Technical details
A broken access control vulnerability (CWE-287/CWE-285) exists in the HestiaCP web panel due to an improperly implemented authorization check in the cron job management component. The check relies on an undefined variable ($ROOT_USER), causing the logic to fail and allowing low-privileged users to modify 'panel cron jobs' that execute as the privileged panel user. Because the panel user has passwordless sudo access to administrative scripts (e.g., v-change-user-password), an authenticated attacker can schedule a task to reset the administrator's password or execute other management commands. The vulnerability is further exacerbated by a lack of CSRF validation on the affected endpoint. A fix was introduced in commit 8be2394.
Affected products
- HestiaCP HestiaCP Prior to commit 8be23943c7e3231f66d226ca931c76f93be98412
Timeline
- 2026-06-23: patched: Fix merged into main branch via Pull Request 5440
- 2026-07-04: disclosed: Public advisory and blog post published
- 2026-07-04: advisory: NVD entry published