CVE-2018-20939: cPanel
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
Affected products
- cPanel cPanel: from 61.9999.55, before 62.0.39 (fixed in 62.0.39); from 65.9999.38, before 66.0.35 (fixed in 66.0.35); from 67.9999.64, before 68.0.27 (fixed in 68.0.27)
Published 2019-08-01. Last modified 2026-06-17.