CVE-2026-32993

Published May 13, 2026

Last updated 10 days ago

Overview

Description
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
Source
support@hackerone.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.3
Impact score
3.7
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-93

Social media

Hype score
Not currently trending
  1. cPanel & WHMでまた深刻な脆弱性5件が修正。CVE-2026-29205、CVE-2026-32993、CVE-2026-32992、CVE-2026-29206、CVE-2026-32991。 https://t.co/HGFXjLmFxd

    @__kokumoto

    15 May 2026

    709 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  2. #cPanel Después de parchear ayer: CVE-2026-29205 CVE-2026-29206 CVE-2026-32991 CVE-2026-32992 CVE-2026-32993 Hoy cPanel nos da la buena nueva de parchear de nuevo todos los servidores con la misma vulnerabilidad: CVE-2026-29205 no es que sea una nueva, es que la de ayer

    @tropicalserver

    14 May 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Actualizados los servidores de clientes a la ultima version de cPanel que ha salido hace 2h. Vulnerabilidades corregidas de riesgo ALTO: CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993.  No es necesaria ninguna acción. #seguridad #cPanel

    @factoriadigital

    13 May 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. PSA Patch your servers again! Landing tomorrow at 1pm EST This is getting tedious This release addresses •CVE-2026-29205 •CVE-2026-29206  •CVE-2026-32991  •CVE-2026-32992  •CVE-2026-32993

    @KenBrubacher

    13 May 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. cPanel / WHM'de yeni güvenlik açıkları duyuruldu. Henüz NVD'de görünmeyen bu açıklar için bugün TSİ 21:00 dan sonra patch çıkacak. İlgili saatten sonra /scripts/upcp --force yapmayı unutmayın. * CVE-2026-29205 * CVE-2026-29206 * CVE-2026-32991 * CVE-2026-32992 *

    @ridvanyagli

    13 May 2026

    157 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes