HestiaCP 1.9.9 Releases Critical Security Patch to Fix Root RCE Flaw
HestiaCP released version 1.9.9 today, addressing a critical privilege escalation vulnerability that allows low-privilege users to execute arbitrary commands as root via the backup exclusions feature. This marks the third consecutive security-focused release in roughly three weeks, following a defensive hardening cycle triggered by what appears to be a comprehensive codebase audit. Lead maintainer Jaap Marcus merged PR #5574 after integrating AI-assisted code review and adding an extensive BATS test suite to validate the tightened config parser. Administrators should run the v-update-hestia script immediately to close the root access window before a CVE is officially assigned.
HestiaCP 1.9.9 Releases Critical Security Patch to Fix Root RCE Flaw @ Linux Compatible
HestiaCP 1.9.9 Releases Critical Security Patch to Fix Root RCE Flaw
HestiaCP has released version 1.9.9 to address a critical privilege escalation vulnerability that allows low-privilege users to execute commands as root through the backup exclusions feature. This update is part of a series of security-focused releases, following a comprehensive code audit, and highlights the importance of immediate upgrades for users running HestiaCP-managed servers. The vulnerability, tracked as GHSA-xffx-jj33-p2px, could allow attackers to gain full administrative control if they compromised a standard hosting account. The patch includes enhanced validation for the exclusions binary and integrates AI-assisted code review, emphasizing the need for administrators to prioritize security updates over new features
