EIP-2026-113056

PRE-CVE

Vesta Control Panel 0.9.8-15 - Persistent Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113056. PoCs published by Necmettin COSKUN.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Vesta Control Panel <= 0.9.8-15 by injecting malicious JavaScript via the User-Agent header, which gets logged and executed when an administrator views the access.log file.

Description

Vesta Control Panel 0.9.8-15 - Persistent Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC
by Necmettin COSKUN · textwebappsphp
https://www.exploit-db.com/exploits/39468

This exploit demonstrates a persistent XSS vulnerability in Vesta Control Panel <= 0.9.8-15 by injecting malicious JavaScript via the User-Agent header, which gets logged and executed when an administrator views the access.log file.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Vesta Control Panel <= 0.9.8-15
No auth needed
Prerequisites: Access to send HTTP requests to the target server · Administrator must view the access.log file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026