Deserialization Vulnerability in HestiaCP Web Terminal Component

⚠️ CVE-Referenzen: CVE-2026-43633
Hestiacp - Hestiacp - CRITICAL - CVE-2026-43633. HestiaCP versions 1.9.0 to 1.9.4 are affected by a deserialization vulnerability within the web terminal component. This flaw arises from a mismatch in session formats between PHP and Node.js, allowing unauthenticated remote attackers to exploit the system. By injecting malicious data into HTTP headers, attackers can manipulate the PHP session handler, leading to improper deserialization by the Node.js component. As a consequence, this could enable arbitrary command execution on systems where the web terminal feature is activated. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io