EIP-2026-113056
PRE-CVEVesta Control Panel 0.9.8-15 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113056. PoCs published by Necmettin COSKUN.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Vesta Control Panel <= 0.9.8-15 by injecting malicious JavaScript via the User-Agent header, which gets logged and executed when an administrator views the access.log file.
Description
Vesta Control Panel 0.9.8-15 - Persistent Cross-Site Scripting
Exploits (1)
exploitdb
WORKING POC
by Necmettin COSKUN · textwebappsphp
https://www.exploit-db.com/exploits/39468
This exploit demonstrates a persistent XSS vulnerability in Vesta Control Panel <= 0.9.8-15 by injecting malicious JavaScript via the User-Agent header, which gets logged and executed when an administrator views the access.log file.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target:
Vesta Control Panel <= 0.9.8-15
No auth needed
Prerequisites:
Access to send HTTP requests to the target server · Administrator must view the access.log file
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026