PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-29202 cPanel CVE debrief

On 2026-05-07, cPanel disclosed CVE-2026-29202, describing a Perl code injection issue in the create_user API call related to the plugin parameter. cPanel says fixed builds are available for affected cPanel & WHM branches, WP Squared 11.136.1.11 and later, and a direct 11.110.0.116 update for CentOS 6 or CloudLinux 6 systems. Administrators should prioritize upgrading any affected systems and verify that automation or tooling that uses the create_user API is running on a patched release.

Vendor
cPanel
Product
cPanel/WHM
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-07
Original CVE updated
2026-05-11
Advisory published
2026-05-07
Advisory updated
2026-05-11

Who should care

cPanel/WHM and WP Squared administrators, especially teams that use the create_user API call in automation or manage legacy CentOS 6 / CloudLinux 6 hosts.

Technical summary

According to the vendor advisory, CVE-2026-29202 is a Perl code injection method affecting the create_user API call and involving the plugin parameter. cPanel states the issue is fixed in cPanel & WHM 11.136.0.9 and later, 11.134.0.25 and later, 11.132.0.31 and later, 11.130.0.22 and later, 11.126.0.58 and later, 11.124.0.37 and later, 11.118.0.66 and later, 11.110.0.117 and later, 11.102.0.41 and later, 11.94.0.30 and later, and 11.86.0.43 and later. WP Squared is fixed in 11.136.1.11 and later. For CentOS 6 or CloudLinux 6, cPanel also released 11.110.0.116 as a direct update.

Defensive priority

High operational priority for any environment exposing or automating cPanel/WHM management, because the affected component is an administrative API path and the vendor has published multiple fixed branches.

Recommended defensive actions

  • Upgrade cPanel & WHM to the first fixed release for your installed branch, or a later patched build.
  • Upgrade WP Squared to 11.136.1.11 or later if applicable.
  • If you are still on CentOS 6 or CloudLinux 6, follow the vendor's documented path to the 11.110.0.116 direct update and set the upgrade tier as instructed by cPanel.
  • Review any automation, integrations, or scripts that call create_user and confirm they are operating against patched versions.
  • Track the vendor advisory for updates and verify all managed servers are on a patched release line.

Evidence notes

This debrief is based on the supplied cPanel vendor advisory summary and the official CVE/NVD links provided in the source corpus. The source corpus does not provide a CVSS score, exploit proof, or additional technical detail beyond the vendor's description and fixed-version list.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-29202 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-29202

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-29202 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-29202

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Vendor advisory source

    Unverified legacy reference

    URL: https://support.cpanel.net/hc/en-us/articles/40311426610327-Security-CVE-2026-29202-cPanel-WHM-WP2-Security-Update-May-08-2026

    cpanel_changelog_rss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.