1.
projectblack.io | research | | original ↗ | #rce | #vulnerability-research | #access-control | #hestiacp
Project Black details CVE-2026-12196 in HestiaCP: a broken authorization check lets any low-privileged user exploit panel cron jobs to run sudo scripts and reset the admin password.
Skip to content