Vulnerability Description
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
Related Weaknesses (CWE)
References
- https://github.com/myvesta/vesta/commit/95d7e43bf286d6881ca753dac93cb42d98cc7422
- https://projectblack.io/blog/local-ai-for-cyber-security/#myvesta-authenticated-
FAQ
What is CVE-2026-12195?
CVE-2026-12195 is a documented vulnerability. myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This ...
How severe is CVE-2026-12195?
CVSS scoring is not yet available for CVE-2026-12195. Check NVD for updates.
Is there a patch for CVE-2026-12195?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.