CVE-2026-29205: cPanel

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Affected products

  • cPanel cPanel: from 120.0.0, before 124.0.38 (fixed in 124.0.38); from 126.0.0, before 126.0.59 (fixed in 126.0.59); from 130.0.0, before 130.0.23 (fixed in 130.0.23); from 130.0.23, before 130.0.23 (fixed in 130.0.23); from 132.0.0, before 132.0.32 (fixed in 132.0.32); from 134.0.0, before 134.0.26 (fixed in 134.0.26); …
  • cPanel WHM: from 120.0.0, before 124.0.38 (fixed in 124.0.38); from 126.0.0, before 126.0.59 (fixed in 126.0.59); from 130.0.0, before 130.0.23 (fixed in 130.0.23); from 132.0.0, before 132.0.32 (fixed in 132.0.32); from 134.0.0, before 134.0.26 (fixed in 134.0.26); from 136.0.0, before 136.0.10 (fixed in 136.0.10)
  • cPanel Wp Squared: from 120.1.0, before 136.1.12 (fixed in 136.1.12)

Published 2026-05-13. Last modified 2026-08-12.