CVE-2020-29136: cPanel

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

Affected products

  • cPanel cPanel: before 11.86.0.32 (fixed in 11.86.0.32); from 11.90.0, before 11.90.0.17 (fixed in 11.90.0.17); from 11.92.0, before 11.92.0.2 (fixed in 11.92.0.2)

Published 2020-11-27. Last modified 2026-06-17.