Hestiacp · Hestiacp · CVE-2026-12196
**Name of the Vulnerable Software and Affected Versions**
HestiaCP (affected versions not specified)
**Description**
The panel cronjob feature contains a broken access control flaw. This allows users with low privileges to modify the panel cronjob to execute HestiaCP management scripts using passwordless sudo, which can lead to the takeover of administrator accounts within the application and the underlying webserver.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.