CVE-2020-36771: Cloudlinux Cagefs

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

Affected products

  • Cloudlinux Cagefs: before 7.1.2-2 (fixed in 7.1.2-2)

Published 2024-01-22. Last modified 2026-06-17.