- Description
- Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
- Source
- support@hackerone.com
- NVD status
- Analyzed
- Products
- cpanel, wp_squared, whm
CVSS 3.1
- Type
- Secondary
- Base score
- 8.6
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- Severity
- HIGH
- support@hackerone.com
- CWE-250
- Hype score
- Not currently trending
The Perfect Storm: cPanel & WHM May 13 Coordinated Release — Five HIGH CVEs, Zero Exploits (Yet). cPanel & WHM is releasing an emergency security patch on May 13, 2026 at 1:00 PM EST addressing five HIGH-severity vulnerabilities CVE-2026-29205, CVE-2026-29206,…
@lyrie_ai
24 Jun 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerabilidades en productos cPanel ❗ CVE-2026-32993 ❗ CVE-2026-32992 ❗ CVE-2026-29205 ➡️ Más info: https://t.co/kYBVYhSH1V https://t.co/XKmd99xRP0
@CERTpy
29 May 2026
96 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-2276 2 - CVE-2026-42945 3 - CVE-2026-20182 4 - CVE-2026-40369 5 - CVE-2026-29205 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
19 May 2026
140 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) https://t.co/wEI1EYfcJk
@Dinosn
19 May 2026
212 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
cPanel & WHMでまた深刻な脆弱性5件が修正。CVE-2026-29205、CVE-2026-32993、CVE-2026-32992、CVE-2026-29206、CVE-2026-32991。 https://t.co/HGFXjLmFxd
@__kokumoto
15 May 2026
709 Impressions
0 Retweets
2 Likes
2 Bookmarks
0 Replies
0 Quotes
#cPanel Después de parchear ayer: CVE-2026-29205 CVE-2026-29206 CVE-2026-32991 CVE-2026-32992 CVE-2026-32993 Hoy cPanel nos da la buena nueva de parchear de nuevo todos los servidores con la misma vulnerabilidad: CVE-2026-29205 no es que sea una nueva, es que la de ayer
@tropicalserver
14 May 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actualizados los servidores de clientes a la ultima version de cPanel que ha salido hace 2h. Vulnerabilidades corregidas de riesgo ALTO: CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993. No es necesaria ninguna acción. #seguridad #cPanel
@factoriadigital
13 May 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PSA Patch your servers again! Landing tomorrow at 1pm EST This is getting tedious This release addresses •CVE-2026-29205 •CVE-2026-29206 •CVE-2026-32991 •CVE-2026-32992 •CVE-2026-32993
@KenBrubacher
13 May 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
cPanel / WHM'de yeni güvenlik açıkları duyuruldu. Henüz NVD'de görünmeyen bu açıklar için bugün TSİ 21:00 dan sonra patch çıkacak. İlgili saatten sonra /scripts/upcp --force yapmayı unutmayın. * CVE-2026-29205 * CVE-2026-29206 * CVE-2026-32991 * CVE-2026-32992 *
@ridvanyagli
13 May 2026
157 Impressions
0 Retweets
5 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8C95EF6B-A471-41FD-8B65-32E3B3A2C066",
"versionEndExcluding": "124.0.38",
"versionStartIncluding": "120.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CF4EC0BD-A3D9-4508-A203-AE7C3FD7B7B4",
"versionEndExcluding": "126.0.59",
"versionStartIncluding": "126.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3C684F0A-4C2D-44DD-8AFB-EDD961B37161",
"versionEndExcluding": "130.0.23",
"versionStartIncluding": "130.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "69C8900C-A2C1-411E-B86D-53B20F07207E",
"versionEndExcluding": "130.0.23",
"versionStartIncluding": "130.0.23",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C72D46EF-7010-4BF0-B227-4FB6F2594956",
"versionEndExcluding": "132.0.32",
"versionStartIncluding": "132.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1111E4FB-BE6E-46B6-B506-44B396A4104A",
"versionEndExcluding": "134.0.26",
"versionStartIncluding": "134.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0193B98A-BF31-48D9-A0A0-F5FEB8E8EE45",
"versionEndExcluding": "136.0.10",
"versionStartIncluding": "136.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "A8ADEB08-7DC8-4B45-B717-E011E48076F1",
"versionEndExcluding": "136.1.12",
"versionStartIncluding": "120.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FDFD9D2E-515E-4BBE-A172-9F562A53DD2C",
"versionEndExcluding": "124.0.38",
"versionStartIncluding": "120.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1DC95DCA-C5D9-48F6-BBA9-7A5AE81DCFEE",
"versionEndExcluding": "126.0.59",
"versionStartIncluding": "126.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2A46F223-05E9-4B7E-86DE-3FC2B33AAE91",
"versionEndExcluding": "130.0.23",
"versionStartIncluding": "130.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0C1C3084-F8B2-44BA-8BEA-0EB13D746061",
"versionEndExcluding": "132.0.32",
"versionStartIncluding": "132.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C6AA26F4-2086-46CC-AA7C-6BACBFF7688B",
"versionEndExcluding": "134.0.26",
"versionStartIncluding": "134.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A3C3BB3C-A3AB-4F56-BE36-F7BC14BB7554",
"versionEndExcluding": "136.0.10",
"versionStartIncluding": "136.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]