CVE-2020-36948

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
Configurations

No configuration.

History

27 Jan 2026, 22:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49219 - () https://www.exploit-db.com/exploits/49219 -
References () https://www.vulnerability-lab.com/get_content.php?id=2240 - () https://www.vulnerability-lab.com/get_content.php?id=2240 -
References () https://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M. - () https://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M. -

27 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 16:16

Updated : 2026-01-29 16:31


NVD link : CVE-2020-36948

Mitre link : CVE-2020-36948

CVE.ORG link : CVE-2020-36948


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization