Impact
HestiaCP versions before 1.9.5 contain an authenticated OS command injection flaw (CWE-78) that permits low‑privilege users to execute arbitrary commands as root when they create or modify DNS records. The vulnerability stems from insufficient input validation in the DNS record format check combined with unsafe eval‑based parsing during zone updates, allowing a single quote that prematurely terminates a variable assignment string. An attacker who can inject such a character during DNS record creation gains full root control over the host, compromising confidentiality, integrity, and availability of all system resources.
Affected Systems
The flaw affects HestiaCP deployments running any version earlier than 1.9.5, accessed via the web based DNS record management interface. Any authenticated user with permission to create or update DNS records can trigger the vulnerability.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of 2% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privilege authenticated session, most likely through the web panel where DNS records are managed. Because the attack results in root privilege escalation, it poses a serious risk to affected hosts.
OpenCVE Enrichment