{"id":"CVE-2026-12195","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-12195","summary":null,"details":"myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta.","published":"2026-07-04T11:33:27.032Z","modified":"2026-08-12T03:51:09.210836642Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/myvesta/vesta/commit/95d7e43bf286d6881ca753dac93cb42d98cc7422","label":"myvesta/vesta@95d7e43"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12195.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12195"},{"type":"FIX","url":"https://github.com/myvesta/vesta/commit/95d7e43bf286d6881ca753dac93cb42d98cc7422"},{"type":"EVIDENCE","url":"https://projectblack.io/blog/local-ai-for-cyber-security/#myvesta-authenticated-rce"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.210836642Z"}}