PT-2026-3823 · Unknown · Hestia Control Panel

Numan Türle

·

Published

2026-01-21

·

Updated

2026-01-21

·

CVE-2021-47871

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hestia Control Panel version 1.3.2
Description An authenticated attacker can write files to arbitrary locations on the server. This is possible through the index.php API endpoint by exploiting the v-make-tmp-file command. Attackers can write content, such as SSH keys, to specific file paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2021-47871

Affected Products

Hestia Control Panel