HestiaCP 1.9.9 Releases Critical Security Patch to Fix Root RCE Flaw

Published by

HestiaCP has released version 1.9.9 to address a critical privilege escalation vulnerability that allows low-privilege users to execute commands as root through the backup exclusions feature. This update is part of a series of security-focused releases, following a comprehensive code audit, and highlights the importance of immediate upgrades for users running HestiaCP-managed servers. The vulnerability, tracked as GHSA-xffx-jj33-p2px, could allow attackers to gain full administrative control if they compromised a standard hosting account. The patch includes enhanced validation for the exclusions binary and integrates AI-assisted code review, emphasizing the need for administrators to prioritize security updates over new features



HestiaCP 1.9.9 Releases Critical Security Patch to Fix Root RCE Flaw

HestiaCP released version 1.9.9 today, addressing a critical privilege escalation vulnerability that allows low-privilege users to execute arbitrary commands as root via the backup exclusions feature. This marks the third consecutive security-focused release in roughly three weeks, following a defensive hardening cycle triggered by what appears to be a comprehensive codebase audit. Lead maintainer Jaap Marcus merged PR #5574 after integrating AI-assisted code review and adding an extensive BATS test suite to validate the tightened config parser. Administrators should run the v-update-hestia script immediately to close the root access window before a CVE is officially assigned.

HestiaCP 1.9.9 Releases Critical Security Patch to Fix Root RCE Flaw @ Linux Compatible