← Vulnerability feed

Vulnerability record · CVE-2020-10808 · published 22 March 2020

CVE-2020-10808: VestaCP backup listing endpoint OS command injection

Vestacp · Vesta Control Panel

Vesta Control Panel through 0.9.8-26 passes filenames from the schedule/backup Backup Listing endpoint into a shell command without sanitization, allowing OS command injection. An attacker who can place a crafted filename on the server, for example by renaming .bash_logout via FTP to include shell metacharacters, can trigger command execution when the backup listing runs.

8.8 CVSS 3.1 High EPSS 78% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring followed by shell metacharacters.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityRemote command injection with public exploit code and very high EPSS probability, but it requires authenticated low-privilege access plus the ability to write a crafted filename.

What it is

Vesta Control Panel through 0.9.8-26 passes filenames from the schedule/backup Backup Listing endpoint into a shell command without sanitization, allowing OS command injection. An attacker who can place a crafted filename on the server, for example by renaming .bash_logout via FTP to include shell metacharacters, can trigger command execution when the backup listing runs.

Impact

An attacker gains arbitrary command execution with the privileges of the VestaCP process, leading to full compromise of the hosting server and any hosted accounts. CVSS 3.1 scores this 8.8 (HIGH) with high confidentiality, integrity and availability impact.

Attack surface

Reached over the network through the VestaCP backup listing functionality; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low-privilege authenticated access is required and no user interaction. The attacker must also be able to create or rename a file on the server, as shown by the FTP rename example.

Exploitation

Public exploit code exists, including Metasploit modules and a detailed second-order RCE writeup, and EPSS is 0.775 (99.5th percentile), though CISA KEV does not list it. No ransomware group usage is documented in the record.

What to do

  • Upgrade VestaCP past 0.9.8-26 to a fixed release; check the vendor forum release notes for the patched version.
  • Restrict FTP and file-write access so untrusted users cannot create or rename files with shell metacharacters on the server.
  • Sanitize or avoid shell invocation when processing backup filenames, and run the panel with least privilege.
  • Limit network exposure of the VestaCP panel and FTP services to trusted addresses.

Detection

  • Monitor VestaCP backup listing activity for filenames containing shell metacharacters such as quotes, semicolons or backticks.
  • Alert on unexpected child processes spawned by the VestaCP web or backup service.
  • Audit FTP rename and upload events for suspicious names like .bash_logout variants.
  • Review panel logs for low-privilege accounts invoking backup listing endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10808 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43693Vestacp vesta control panel vulnerabilityvesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.EPSS 1.2%9.8CVE-2018-1000884Vestacp vesta control panel observable discrepancy vulnerabilityVesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure …EPSS 1.3%8.8CVE-2021-28379Myvestacp myvesta unrestricted file upload vulnerabilityweb/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different or…EPSS 6.0%8.8CVE-2020-10786Vestacp vesta control panel incorrect authorization vulnerabilityA remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron…EPSS 4.8%8.8CVE-2020-10787Vestacp vesta control panel vulnerabilityAn elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-u…EPSS 2.5%8.8CVE-2019-9859Vestacp vesta control panel os command injection vulnerabilityVesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the…EPSS 3.0%7.2CVE-2021-46850Vestacp control panel argument injection vulnerabilitymyVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote adm…EPSS 5.4%7.2CVE-2021-30462Vestacp vesta control panel missing authentication for critical function vulnerabilityVestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-10808), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.