8.6

CVE-2026-29205

Medienbericht
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CpanelCpanel Version >= 120.0.0 < 124.0.38
CpanelCpanel Version >= 126.0.0 < 126.0.59
CpanelCpanel Version >= 130.0.0 < 130.0.23
CpanelCpanel Version >= 130.0.23 < 130.0.23
CpanelCpanel Version >= 132.0.0 < 132.0.32
CpanelCpanel Version >= 134.0.0 < 134.0.26
CpanelCpanel Version >= 136.0.0 < 136.0.10
CpanelWp Squared SwPlatformwordpress Version >= 120.1.0 < 136.1.12
CpanelWhm Version >= 120.0.0 < 124.0.38
CpanelWhm Version >= 126.0.0 < 126.0.59
CpanelWhm Version >= 130.0.0 < 130.0.23
CpanelWhm Version >= 132.0.0 < 132.0.32
CpanelWhm Version >= 134.0.0 < 134.0.26
CpanelWhm Version >= 136.0.0 < 136.0.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.15% 0.943
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HackerOne 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CWE-250 Execution with Unnecessary Privileges

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 12:44
https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026
Patch
Vendor Advisory