EIP-2026-103027
PRE-CVEVesta Control Panel 0.9.8-16 - Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103027. PoCs published by Jaka Hudoklin.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Vesta Control Panel's 'v-get-web-domain-value' script, which is executable via sudo without a password for the 'admin' user. It injects a malicious command to create a SUID shell, escalating privileges from the admin user to root.
Description
Vesta Control Panel 0.9.8-16 - Local Privilege Escalation
Exploits (1)
This exploit leverages a command injection vulnerability in Vesta Control Panel's 'v-get-web-domain-value' script, which is executable via sudo without a password for the 'admin' user. It injects a malicious command to create a SUID shell, escalating privileges from the admin user to root.