What the vulnerability does
01Description
Missing Authorization vulnerability in Juni Hestia Nginx Cache hestia-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through <= 2.4.0.
Explanation of Vulnerability in Simple Terms
02Summary
Hestia Nginx Cache versions 2.4.0 and earlier lack proper authorization checks, allowing an unauthenticated attacker to modify cached content or settings through a crafted request. The attacker must trick a site visitor into clicking a malicious link or visiting a compromised page. This affects data integrity but not confidentiality or availability.
What an attacker can do
03Attacker Capabilities
Modify cached content or cache settings without authentication.
Potential impact on your site
04Site Impact
Cached pages could be poisoned with malicious content served to visitors until cache expires.
Conditions required to exploit
05Prerequisites
No login required. Victim must click a malicious link or visit attacker-controlled page.
Key dates
06Disclosure timeline
January 2, 2025
CVE published
April 28, 2026
Record updated