CVE-2026-29203: WebPros cPanel
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home directory.
Affected products
- WebPros cPanel: from 11.136.0.0, before 11.136.0.9 (fixed in 11.136.0.9); from 11.134.0.0, before 11.134.0.25 (fixed in 11.134.0.25); from 11.132.0.0, before 11.132.0.31 (fixed in 11.132.0.31); from 11.130.0.0, before 11.130.0.22 (fixed in 11.130.0.22); from 11.126.0.0, before 11.126.0.58 (fixed in 11.126.0.58); from 11.124.0.0, before 11.124.0.37 (fixed in 11.124.0.37); …
- WebPros cPanel Cloudlinux 6, Centos 6: from 11.110.0.0, before 11.110.0.116 (fixed in 11.110.0.116)
- WebPros Wp Squared: from 11.136.1.0, before 11.136.1.10 (fixed in 11.136.1.10)
Published 2026-05-08. Last modified 2026-06-17.