Junglewise Threat Intelligence

CVE-2026-43633: HestiaCP deserialization in web terminal component

CVE-2026-43633 · Severity: critical · CVSS 10 · Published 2026-05-19

Vendors: HestiaCP.

Executive brief

HestiaCP, a popular open-source control panel for web servers, contains a critical vulnerability in its web terminal feature. An unauthenticated attacker can exploit a mismatch in how different parts of the software handle user sessions to execute commands with the highest level of system privileges (root). This could allow a remote attacker to take full control of the server, access sensitive customer data, or disrupt hosted services.

Technical details

A deserialization vulnerability (CWE-502) exists in HestiaCP due to a session format mismatch between the PHP-based backend and the Node.js-based web terminal component. Attackers can inject crafted data into HTTP headers that are initially processed by the PHP session handler. When the Node.js web terminal component subsequently attempts to deserialize these values, it incorrectly treats the attacker-controlled data as trusted session objects. This allows an unauthenticated remote attacker to achieve arbitrary command execution with root privileges on systems where the web terminal feature is enabled. The issue was addressed by moving session authentication lookups to a PHP helper to ensure consistent data handling.

Affected products

  • HestiaCP Hestia Control Panel (HestiaCP) 1.9.0 through 1.9.4

Timeline

  • 2026-01-16: other: Initial notification sent to vendor
  • 2026-02-20: disclosed: Public issue opened on GitHub after lack of vendor response
  • 2026-03-08: patched: Fix merged into main branch via pull request #5244
  • 2026-05-19: advisory: CVE published to NVD

References

Related threats