CVE-2019-17375: cPanel

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).

Affected products

  • cPanel cPanel: from 81.9999.242, before 82.0.15 (fixed in 82.0.15)

Published 2019-10-09. Last modified 2026-06-17.