Impact
A broken access control flaw in the HestiaCP panel’s cronjob feature allows a low‑privilege user to modify scheduled tasks that run HestiaCP management scripts with password‑less sudo privileges. By editing a cron entry the attacker can trigger commands that execute with root privileges, effectively taking over both the HestiaCP application’s administrator accounts and, if sufficient privileges exist, the underlying web server. The weakness is a classic Broken Access Control (CWE‑287).
Affected Systems
The vulnerability affects installations of the HestiaCP control panel. No specific product version is listed, so the issue may be present in any HestiaCP instance until the published fix is applied.
Risk and Exploitability
The CVSS base score of 8.3 indicates a high‑severity vulnerability with impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is currently uncommon, and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated low‑privilege account on the HestiaCP web interface; the attacker must then edit a cronjob entry and rely on password‑less sudo permissions for HestiaCP scripts. Thus the likely attack vector is local and confined to the web panel, with the attacker needing only a valid user session.
OpenCVE Enrichment