{"id":"CVE-2026-12195","title":"myVesta is affected by an authenticated remote code execution vulnerability","summary":"myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of comm…","severity":"none","cwe":["CWE-78"],"published":"2026-07-04","updated":"2026-07-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12195","references":[{"url":"https://github.com/myvesta/vesta/commit/95d7e43bf286d6881ca753dac93cb42d98cc7422","label":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a"},{"url":"https://projectblack.io/blog/local-ai-for-cyber-security/#myvesta-authenticated-rce","label":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a"}],"tags":["nvd"],"ingestedAt":"2026-07-04T21:57:46.880Z","epss":0.00656,"epssPercentile":0.50028,"slug":"CVE-2026-12195","body":"## Overview\n\nmyVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}