NONE · 0

CVE-2026-12196

HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless s...

Vulnerability Description

HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless sudo. This could result in the takeover of administrator users in the application and the underlying webserver.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-12196?

CVE-2026-12196 is a documented vulnerability. HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the panel cronjob to execute scripts HestiaCP management scripts with passwordless s...

How severe is CVE-2026-12196?

CVSS scoring is not yet available for CVE-2026-12196. Check NVD for updates.

Is there a patch for CVE-2026-12196?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.