Vulnerabilities · 129 days ago

cPanel Control-Plane Flaws Expose Hosted Sites

cPanel flaws are not just panel bugs. They hit the hosting control plane, so an authenticated account can move from one login to code execution, file reads, or permission changes that affect customer sites and data across a shared environment.

cPanel and WHM now patch CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The issues cover arbitrary file read, arbitrary Perl code execution on behalf of an already authenticated account’s system user, and unsafe symlink handling that can alter permissions on arbitrary files; fixed builds include 11.136.0.9, 11.134.0.25, 11.132.0.31, 11.130.0.22, 11.126.0.58, 11.124.0.37, 11.118.0.66, 11.110.0.116, and 11.110.0.117 or higher.

There is no evidence of in-the-wild exploitation for these three flaws. The risk that persists is blast radius: in shared hosting, compromise does not stay confined to the panel host, because the panel is the layer that manages customer accounts, permissions, and hosted content.

CVE-2026-29202

NVD KEV

CVSS 8.8 HIGH: insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code…

CVE-2026-29203

NVD KEV

CVSS 8.8 HIGH: a chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories.

CVE-2026-29201

NVD KEV

CVSS 4.3 MEDIUM: insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause…

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-10

Editions