CVE-2026-43634 Details
Description
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.
An IP spoofing vulnerability has been identified in HestiaCP versions 1.2.0 through 1.9.4. This vulnerability allows unauthenticated remote attackers to bypass authentication security measures by injecting arbitrary IP addresses into the CF-Connecting-IP HTTP header. The issue arises because the application does not verify whether the request originated from Cloudflare's network. Exploitation of this vulnerability can circumvent fail2ban's brute-force protection, bypass per-user IP allowlists, and corrupt authentication audit logs by spoofing trusted IP addresses with each request.
Users are advised to update to the latest version of HestiaCP, where this vulnerability has been fixed. As an immediate measure, restrict access to port 8083 to trusted IP ranges at the firewall level.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hestiacp/hestiacp/commit/f381e294500f671cf12716c638afd0bfde901f88 | [email protected] | Source CodeVendor |
| https://github.com/hestiacp/hestiacp/issues/5229 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/hestiacp/hestiacp/pull/5273 | [email protected] | Issue TrackingVendor |
| https://mercuryiss.com.au/hestiacp-unauthenticated-rce-ip-spoofing-cve-2026-43633-cve-2026-43634 | [email protected] | BundleRemedyTechnical Analysis |
| https://www.vulncheck.com/advisories/hestiacp-ip-spoofing-via-cf-connecting-ip-header | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| HestiaCP | >= 1.2.0, <= 1.9.4 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |
Volerion