CVE-2026-29202
CVSS 8.8 HIGH: insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code…
Vulnerabilità · 143 giorni fa
Le falle di cPanel non sono solo bug del panel. Colpiscono il piano di controllo dell’hosting, quindi un account autenticato può passare da un singolo login a esecuzione di codice, lettura di file o modifiche dei permessi che interessano i siti dei clienti e i dati in un ambiente condiviso.
CVSS 8.8 HIGH: insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code…
CVSS 8.8 HIGH: a chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories.
CVSS 4.3 MEDIUM: insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause…
1 fonte che coprono questa storia
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
cPanel patched three vulnerabilities, including two 8.8 CVSS flaws, reducing risks of code execution and privilege escalation.
Part of the PlainSec briefing for 2026-05-10