CVE-2020-10787: Vestacp Vesta Control Panel
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).
Affected products
- Vestacp Vesta Control Panel: up to and including 0.9.8-26
Published 2020-04-21. Last modified 2026-06-17.