CVE-2019-18418: Clonos

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

Affected products

  • Clonos Clonos: version 19.09 only

Published 2019-10-24. Last modified 2026-06-17.