← Vulnerability feed

Vulnerability record · CVE-2022-2550 · published 27 July 2022

CVE-2022-2550: HestiaCP control panel OS command injection

Hestiacp · Control Panel

HestiaCP versions prior to 1.6.5 contain an OS command injection flaw (CWE-78) in the control panel. A remote attacker with low-privileged credentials can inject operating system commands that execute on the server, compromising the hosting environment. The vendor has released a patch in 1.6.5.

8.8 CVSS 3.1 High EPSS 48% · top 1.2% CWE-78 · OS command injection
8.8CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityHigh CVSS (8.8) remote command injection with a public exploit reference and very high EPSS, though it requires low-privileged authentication and is not in KEV.

What it is

HestiaCP versions prior to 1.6.5 contain an OS command injection flaw (CWE-78) in the control panel. A remote attacker with low-privileged credentials can inject operating system commands that execute on the server, compromising the hosting environment. The vendor has released a patch in 1.6.5.

Impact

An authenticated low-privilege attacker can execute arbitrary OS commands on the HestiaCP server, leading to full compromise of confidentiality, integrity and availability of the host and hosted data.

Attack surface

Reachable over the network via the control panel interface (CVSS vector AV:N). Exploitation requires low privileges (PR:L) but no user interaction (UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.483 (98.8th percentile) and a public exploit reference exists on huntr.dev, indicating active interest and likely availability of exploit code.

What to do

  • Upgrade HestiaCP to version 1.6.5 or later immediately.
  • Restrict control panel access to trusted networks or VPN and enforce strong authentication.
  • Audit and minimize low-privilege accounts that can reach the panel.
  • Monitor server processes and logs for unexpected command execution originating from the panel.
  • Apply the vendor commit patch if an immediate full upgrade is not possible.

Detection

  • Review HestiaCP and web server logs for suspicious command strings or shell metacharacters in panel requests.
  • Monitor for child processes spawned by the panel web service executing system commands.
  • Alert on new or unusual outbound connections from the HestiaCP host.
  • Check for unexpected files or cron entries created after panel activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2550 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-3797Hestiacp control panel vulnerabilityhestiacp is vulnerable to Use of Wrong Operator in String ComparisonEPSS 1.1%8.8CVE-2022-2636Hestiacp control panel code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.EPSS 1.3%8.8CVE-2022-1509Hestiacp control panel command injection vulnerabilityCommand Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can exec…EPSS 4.5%8.7CVE-2025-30007Hestiacp control panel os command injection vulnerabilityHestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary…EPSS 3.2%7.8CVE-2023-5839Hestiacp control panel vulnerabilityPrivilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.EPSS 0.29%7.2CVE-2022-2626Hestiacp control panel vulnerabilityIncorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.EPSS 1.2%6.5CVE-2020-10966Hestiacp control panel vulnerabilityIn the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account…EPSS 1.9%6.1CVE-2023-3479Hestiacp control panel cross-site scripting vulnerabilityCross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2022-2550), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.