CVE-2017-18428: cPanel

Low severity, CVSS 2.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).

Affected products

  • cPanel cPanel: from 55.9999.61, before 56.0.51 (fixed in 56.0.51); from 57.9999.48, before 58.0.52 (fixed in 58.0.52); from 59.9999.58, before 60.0.45 (fixed in 60.0.45); from 61.9999.55, before 62.0.27 (fixed in 62.0.27); from 63.9999.74, before 64.0.33 (fixed in 64.0.33); from 65.9999.38, before 66.0.2 (fixed in 66.0.2)

Published 2019-08-02. Last modified 2026-06-17.