EIP-2026-104479
PRE-CVEVestaCP 0.9.8-26 - 'backup' Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104479. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This advisory details an insufficient session validation vulnerability in VestaCP 0.9.8-26, allowing remote attackers to download backup files without proper authentication by omitting the token parameter. The writeup includes technical details, affected modules, and proof-of-concept URLs.
Description
VestaCP 0.9.8-26 - 'backup' Information Disclosure
Exploits (1)
This advisory details an insufficient session validation vulnerability in VestaCP 0.9.8-26, allowing remote attackers to download backup files without proper authentication by omitting the token parameter. The writeup includes technical details, affected modules, and proof-of-concept URLs.