Vulnerability record · CVE-2020-10808 · published 22 March 2020
CVE-2020-10808: VestaCP backup listing endpoint OS command injection
Vestacp · Vesta Control Panel
Vesta Control Panel through 0.9.8-26 passes filenames from the schedule/backup Backup Listing endpoint into a shell command without sanitization, allowing OS command injection. An attacker who can place a crafted filename on the server, for example by renaming .bash_logout via FTP to include shell metacharacters, can trigger command execution when the backup listing runs.
Description
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring followed by shell metacharacters.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command injection with public exploit code and very high EPSS probability, but it requires authenticated low-privilege access plus the ability to write a crafted filename.
What it is
Vesta Control Panel through 0.9.8-26 passes filenames from the schedule/backup Backup Listing endpoint into a shell command without sanitization, allowing OS command injection. An attacker who can place a crafted filename on the server, for example by renaming .bash_logout via FTP to include shell metacharacters, can trigger command execution when the backup listing runs.
Impact
An attacker gains arbitrary command execution with the privileges of the VestaCP process, leading to full compromise of the hosting server and any hosted accounts. CVSS 3.1 scores this 8.8 (HIGH) with high confidentiality, integrity and availability impact.
Attack surface
Reached over the network through the VestaCP backup listing functionality; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low-privilege authenticated access is required and no user interaction. The attacker must also be able to create or rename a file on the server, as shown by the FTP rename example.
Exploitation
Public exploit code exists, including Metasploit modules and a detailed second-order RCE writeup, and EPSS is 0.775 (99.5th percentile), though CISA KEV does not list it. No ransomware group usage is documented in the record.
What to do
- Upgrade VestaCP past 0.9.8-26 to a fixed release; check the vendor forum release notes for the patched version.
- Restrict FTP and file-write access so untrusted users cannot create or rename files with shell metacharacters on the server.
- Sanitize or avoid shell invocation when processing backup filenames, and run the panel with least privilege.
- Limit network exposure of the VestaCP panel and FTP services to trusted addresses.
Detection
- Monitor VestaCP backup listing activity for filenames containing shell metacharacters such as quotes, semicolons or backticks.
- Alert on unexpected child processes spawned by the VestaCP web or backup service.
- Audit FTP rename and upload events for suspicious names like .bash_logout variants.
- Review panel logs for low-privilege accounts invoking backup listing endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-10808 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10808), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.