CVE-2026-29202
CVSS 8.8 HIGH: insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code…
Vulnerabilità ed exploit
Le falle di cPanel non sono solo bug del panel. Colpiscono il piano di controllo dell’hosting, quindi un account autenticato può passare da un singolo login a esecuzione di codice, lettura di file o modifiche dei permessi che interessano i siti dei clienti e i dati in un ambiente condiviso.
1 fonte · 9 mag
CVSS 8.8 HIGH: insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code…
CVSS 8.8 HIGH: a chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories.
CVSS 4.3 MEDIUM: insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause…
The Hacker News
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
cPanel patched three vulnerabilities, including two 8.8 CVSS flaws, reducing risks of code execution and privilege escalation.
originalePart of the PlainSec briefing for 2026-05-10
Every edition of this story: Le falle del piano di controllo di cPanel espongono i siti ospitati