Back to overview

CVE-2026-12195

HIGH
8.5
CVSS 4.0
Description
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.

Metadata

CVE ID
CVE-2026-12195
State
PUBLISHED
Assigner
PRJBLK
Reserved
2026-06-14 07:01 UTC
Published
2026-07-04 11:33 UTC
Last updated
2026-07-04 11:33 UTC
Primary CWE
CWE-78
CWE-78 Improper neutralization of special elements used in a…
Vendor / Product
myvesta / vesta
Sources
cve.org  ·  NVD

Severity & Metrics

8.5 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Affected products (1)
VendorProductPlatformVersions
myvesta vesta 0 < 95d7e43bf286d6881ca753dac93cb42d98cc7422
Weakness (CWE)
CWESourceDescription
CWE-78 cna CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.5 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Back to overview