Impact
A broken access control flaw in HestiaCP’s cronjob management lets anyone with a low‑privilege account edit scheduled tasks that invoke the panel’s management scripts with password‑less sudo permissions. The attacker can queue commands that run with root privileges, enabling a takeover of both application administrators and the underlying web server. The weakness is a classic Broken Access Control (CWE‑287).
Affected Systems
Any installation of the HestiaCP control panel may be affected, as no specific product version is listed; the issue applies to all instances until the published fix is applied.
Risk and Exploitability
The CVSS base score of 8.3 indicates a high‑severity vulnerability that can compromise confidentiality, integrity, and availability. The EPSS score of less than 1% shows that exploitation is currently uncommon, and the vulnerability is not present in CISA KEV. Exploitation requires an authenticated low‑privilege session on the web panel, after which the attacker must modify a cron entry and then relies on password‑less sudo rights for HestiaCP scripts. The likely attack vector is local and confined to the panel, with the attacker needing only a valid user session.
OpenCVE Enrichment