CVE-2017-18430: cPanel

Medium severity, CVSS 4.7. EPSS: 0.7% chance of exploitation in the next 30 days.

In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).

Affected products

  • cPanel cPanel: from 55.9999.61, before 56.0.51 (fixed in 56.0.51); from 57.9999.48, before 58.0.52 (fixed in 58.0.52); from 59.9999.58, before 60.0.45 (fixed in 60.0.45); from 61.9999.55, before 62.0.27 (fixed in 62.0.27); from 63.9999.74, before 64.0.33 (fixed in 64.0.33); from 65.9999.38, before 66.0.2 (fixed in 66.0.2)

Published 2019-08-02. Last modified 2026-06-17.