Description
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
Published: 2026-07-04
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

myVesta contains an authenticated remote code execution flaw that allows users with low privileges to inject arbitrary commands by supplying specially crafted values to the v_ftp_user parameter during the deletion of FTP users., identified as CWE-78. No specific version range is listed, so all deployments of myVesta are potentially impacted unless a later release contains a fix.

Affected Systems

The product affected by this vulnerability is myVesta vesta, as identified by the CNA. Because no specific version range is provided, every release of this product is potentially impacted. The flaw is accessed through the myVesta web interface and requires authenticated access with low privileges, typically an FTP account that can delete users. Admin or privileged users are at risk of command execution and potential takeover of the management interface.

Risk and Exploitability

The CVSS base score is 8.5, indicating a high severity. The EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access. A low‑privileged account that can delete FTP users may be leveraged to inject malicious commands, leading to full administrative takeover.

Generated by OpenCVE AI on July 22, 2026 at 13:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update when a fix is released by the vendor.
  • If an update is unavailable, restrict or disable the ability for low‑privileged users to delete FTP accounts and enforce strict input validation on the v_ftp_user parameter.
  • Apply the myVesta management interface to trusted administrators only.

Generated by OpenCVE AI on July 22, 2026 at 13:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title myVesta Authenticated Remote Code Execution via v_ftp_user Parameter

Wed, 15 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter in myVesta

Tue, 14 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter in myVesta

Sun, 12 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter

Sat, 11 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via v_ftp_user Parameter

Fri, 10 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via v_ftp_user Parameter in myVesta

Thu, 09 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via v_ftp_user Parameter in myVesta

Wed, 08 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Tue, 07 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Tue, 07 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Deletion

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Deletion

Mon, 06 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Delete Parameter in myVesta

Mon, 06 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via FTP Username Delete Parameter in myVesta

Sun, 05 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Sun, 05 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution via Command Injection in myVesta FTP User Deletion

Sun, 05 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution in myVesta via FTP Username Deletion

Sat, 04 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution in myVesta via FTP Username Deletion

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: PRJBLK

Published:

Updated: 2026-07-06T18:31:10.303Z

Reserved: 2026-06-14T07:01:17.476Z

Link: CVE-2026-12195

cve-icon Vulnrichment

Updated: 2026-07-06T18:30:47.149Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:15:12Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')