Description
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
Published: 2026-07-04
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

myVesta is vulnerable to an authenticated remote code execution flaw that allows low‑privileged users to inject arbitrary operating‑system commands through the v_ftp_user parameter when deleting FTP user accounts. The defect is identified as CWE‑78 (OS Command Injection). An attacker who can authenticate within the myVesta web interface and has permission to delete FTP accounts could craft a malicious v_ftp_user payload, causing the system to execute the supplied commands as the admin user and potentially gain full administrative control.

Affected Systems

The affected product is myVesta, identified by the CNA as myvesta:vesta. No specific version range is listed in the CNA data, so every released version of myVesta that includes the deletion functionality could be impacted. Administrators should review their deployments to confirm whether the v_ftp_user deletion path is present and whether users with low privileges can execute it.

Risk and Exploitability

The CVSS base score of 8.5 indicates a high severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low current exploitation probability. However, because the flaw requires authenticated access and low‑privileged accounts that can delete FTP users are fairly common, the risk of exploitation remains non‑negligible. If an attacker succeeds, the arbitrary command execution can lead to full administrative takeover of the myVesta installation.

Generated by OpenCVE AI on August 1, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a revision that contains the fix for the v_ftp_user command injection.
  • If no patch is available, restrict the ability to delete FTP accounts to privileged administrators and enforce strict input validation or sanitization on the v_ftp_user parameter.
  • Limit access to the myVesta management interface by network segmentation or firewall rules to trusted administrators only.

Generated by OpenCVE AI on August 1, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title myVesta Authenticated OS Command Injection Leading to Remote Code Execution

Wed, 29 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Myvestacp
Myvestacp myvesta
Vendors & Products Myvestacp
Myvestacp myvesta

Sat, 25 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title myVesta Authenticated Remote Code Execution via v_ftp_user Parameter

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title myVesta Authenticated Remote Code Execution via v_ftp_user Parameter

Wed, 15 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter in myVesta

Tue, 14 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter in myVesta

Sun, 12 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter

Sat, 11 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter

Fri, 10 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via v_ftp_user Parameter in myVesta

Thu, 09 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via v_ftp_user Parameter in myVesta

Wed, 08 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Tue, 07 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Tue, 07 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Deletion

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Deletion

Mon, 06 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Delete Parameter in myVesta

Mon, 06 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Delete Parameter in myVesta

Sun, 05 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Sun, 05 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Sun, 05 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution in myVesta via FTP Username Deletion

Sat, 04 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution in myVesta via FTP Username Deletion

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Myvestacp Myvesta
cve-icon MITRE

Status: PUBLISHED

Assigner: PRJBLK

Published:

Updated: 2026-07-06T18:31:10.303Z

Reserved: 2026-06-14T07:01:17.476Z

Link: CVE-2026-12195

cve-icon Vulnrichment

Updated: 2026-07-06T18:30:47.149Z

cve-icon NVD

Status : Deferred

Published: 2026-07-04T12:16:53.300

Modified: 2026-07-06T19:43:54.290

Link: CVE-2026-12195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T19:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')