VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
References
Configurations
No configuration.
History
27 Jan 2026, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/49219 - | |
| References | () https://www.vulnerability-lab.com/get_content.php?id=2240 - | |
| References | () https://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M. - |
27 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-27 16:16
Updated : 2026-01-29 16:31
NVD link : CVE-2020-36948
Mitre link : CVE-2020-36948
CVE.ORG link : CVE-2020-36948
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
