CVE-2020-10787: Vestacp Vesta Control Panel

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).

Affected products

  • Vestacp Vesta Control Panel: up to and including 0.9.8-26

Published 2020-04-21. Last modified 2026-06-17.