PatchSiren

cPanel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL cPanel CVE published 2026-09-18

CVE-2026-87900

A security issue was found in WP Toolkit's handling of database-creation commands. Successful exploitation allows authenticated cPanel users to perform database modifications in other accounts. This issue requires immediate attention from cPanel administrators and users with database creation and modification permissions to assess exposure and update WP Toolkit to version 6.11.3 or later. The vulnerabilit [truncated]

CRITICAL cPanel CVE published 2026-09-18

CVE-2026-87899

CVE-2026-87899 is a privilege escalation vulnerability in cPanel's CalDAV and CardDAV functionality. An authenticated cPanel account holder can exploit this vulnerability to escalate their privileges, potentially leading to code execution as the root user. This gives an attacker full control of the server. The vulnerability affects cPanel/WHM versions v120 or later, and patched versions are available.

HIGH cPanel CVE published 2026-09-15

CVE-2026-68490

A permissions issue in cPanel's CalDAV/CardDAV functionality could allow a local user to access calendar and contact data belonging to other accounts on the same server. Successful exploitation allows reading of calendar events and contacts, but does not grant modification or root access. Update to the latest patched version to correct permissions and repair existing accounts.

Review cPanel CVE published 2026-09-02

CVE-2026-67401

CVE-2026-67401 debrief based on cPanel changelog RSS feed and CVE Program record. The vulnerability is a SQL injection issue in cPanel's EmailTrack functionality, allowing authenticated account holders with mail-related privileges to create arbitrary files, potentially leading to code execution as the root user. cPanel administrators and security teams should verify exposure, review mail-related privilege [truncated]

HIGH cPanel CVE published 2026-08-24

CVE-2026-65643

CVE-2026-65643 is a high-severity vulnerability in cPanel's Domain Parking functionality. An authenticated cPanel account holder can create arbitrary files on the server, potentially leading to code execution as the root user. This vulnerability allows an attacker to gain full control of the server and its accounts, websites, and databases. System administrators and security teams responsible for cPanel/W [truncated]

MEDIUM cPanel CVE published 2026-07-28

CVE-2026-58047

The CVE-2026-58047 vulnerability is an HTTP Request Smuggling issue in the cPanel web server. This vulnerability allows manipulation of cpsrvd responses under limited conditions, potentially enabling an unauthenticated remote attacker to manipulate responses delivered to other users on the same server. The vulnerability affects cPanel/WHM and has been patched in versions 11.110.0.137, 11.126.0.78, 11.134. [truncated]

HIGH cPanel CVE published 2026-07-14

CVE-2026-27135

cPanel’s EasyApache 4 25.52 maintenance release includes a security update for ea-nghttp2 and identifies CVE-2026-27135 as the fixed issue. The vendor advisory does not provide technical detail about the flaw in the supplied corpus, but it does make clear that this release is part of a broader EasyApache update cycle that also includes other package refreshes and compatibility fixes.

HIGH cPanel CVE published 2026-06-09

CVE-2026-45447

A security and maintenance update for EasyApache 4 (version 25.66) was released, addressing five CVEs, including four High-severity issues (CVE-2026-45447, CVE-2026-34180, CVE-2026-7383, CVE-2026-9076). The update patches ea-openssl11 to 1.1.1w-8 (for CentOS 7 only) with TuxCare/ELS backports and updates the Passenger ecosystem to v6.1.5. This release aims to enhance security and stability for users of cPanel/WHM.

CRITICAL cPanel CVE published 2026-06-05

CVE-2026-47365

A argument injection vulnerability in WP Toolkit before version 6.11.0, as bundled with cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization boundaries and execute arbitrary wp-toolkit CLI commands under the context of another account. The flaw exists in how WP Toolkit handles command-line arguments, permitting injection that subverts intended tenant isolation on multi-user [truncated]

CRITICAL cPanel CVE published 2026-05-22

CVE-2026-9256

cPanel released a security update for ea-nginx, moving the package to version 1.31.1 to address CVE-2026-9256. The vendor describes the issue as a security vulnerability tied to ea-nginx's ngx_http_rewrite_module and notes remote code execution risk through worker process memory pool handling ("nginx-poolslip"). Administrators running cPanel/WHM with ea-nginx installed should prioritize the update.

HIGH cPanel CVE published 2026-05-14

CVE-2026-32991

cPanel disclosed CVE-2026-32991 on 2026-05-13. According to the vendor advisory, a low-privilege team user with the default role could escalate to the owner account’s full capabilities through certain UAPI modules. The issue affects cPanel & WHM versions 110 and higher, and cPanel has released fixed builds across supported branches, plus a WP Squared fix. Because this is an authenticated privilege-escalat [truncated]

HIGH cPanel CVE published 2026-05-14

CVE-2026-29206

cPanel disclosed CVE-2026-29206 as a SQL injection issue in the sqloptimizer script affecting all cPanel & WHM versions. The vendor states patched releases are available for cPanel & WHM and WP Squared, and recommends extra upgrade-tier steps for customers still on CentOS 6 or CloudLinux 6.

HIGH cPanel CVE published 2026-05-14

CVE-2026-32993

CVE-2026-32993 is a vendor-reported vulnerability in cPanel’s cpsrvd service where an unauthenticated endpoint could allow arbitrary HTTP header insertion. cPanel says the issue affects cPanel & WHM versions 132 and higher and was patched in specific release lines published on 2026-05-13.

HIGH cPanel CVE published 2026-05-13

CVE-2026-32992

cPanel published a security update on 2026-05-13 for CVE-2026-32992. The vendor says SSL verification was not fully enforced in the DNS Cluster system, which could let a malicious server man-in-the-middle a request and capture credentials. cPanel released fixes in specific cPanel & WHM branches and in WP Squared, and states that later versions are also patched.

CRITICAL cPanel CVE published 2026-05-13

CVE-2026-42945

cPanel’s EasyApache 4 25.60 update addresses CVE-2026-42945, described by the vendor as a critical heap buffer overflow in ngx_http_rewrite_module affecting ea-nginx versions v1.30.0 through v1.31.0. The release also rebuilds ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the patched nginx build. For organizations using EasyApache 4 with ea-nginx, this is a high-priorit [truncated]

HIGH cPanel CVE published 2026-05-13

CVE-2026-29205

cPanel disclosed CVE-2026-29205 on 2026-05-13 and updated the advisory on 2026-05-14 with an additional fix. According to the vendor, incorrect privilege dropping combined with insufficient path filtering in certain cpdavd endpoints made it possible to read arbitrary files on affected cPanel & WHM systems. The issue affects cPanel & WHM version 120 and higher, and the vendor recommends moving to the patch [truncated]

CRITICAL cPanel CVE published 2026-05-12

CVE-2026-45185

CVE-2026-45185, also called Dead.Letter, is described as a use-after-free in Exim BDAT message body parsing when TLS is handled by GnuTLS. cPanel’s official advisory states its Exim build does not set USE_GNUTLS, depends on OpenSSL instead, and is not affected.

Review cPanel CVE published 2026-05-12

CVE-2026-43515

cPanel’s EasyApache 4 25.59 security release, published on 2026-05-12, explicitly includes a fix for CVE-2026-43515. In the supplied vendor material, cPanel does not describe the flaw’s root cause, affected component details, or exploitation impact for this CVE, so the safest interpretation is that it should be treated as a security-relevant update for EasyApache 4 users until exposure is ruled out in you [truncated]

HIGH cPanel CVE published 2026-05-12

CVE-2026-28387

CVE-2026-28387 is addressed in cPanel’s EasyApache 4 25.54 release, which delivers a security patch for ea-openssl11. The vendor advisory groups this issue with related OpenSSL package CVEs in the same update stream, so the practical response is to treat the EasyApache 4 package refresh as the fix path for affected cPanel/WHM systems.

HIGH cPanel CVE published 2026-05-10

CVE-2026-6735

cPanel’s EasyApache 4 25.58 security release, published on 2026-05-10, includes a fix for CVE-2026-6735 alongside several other CVEs. The vendor notice says updated packages were released for ea-php82, ea-php83, ea-php84, and ea-php85. The supplied advisory does not provide technical root-cause details for CVE-2026-6735, so the safest takeaway is operational: ensure the EasyApache 4 PHP packages are updat [truncated]

Review cPanel CVE published 2026-05-07

CVE-2026-29203

cPanel disclosed an unsafe symlink handling flaw in cPanel & WHM / WP Squared that could let a user chmod an arbitrary file. The vendor says this can cause denial of service and may enable privilege escalation, and it has released patched builds across supported branches.

Review cPanel CVE published 2026-05-07

CVE-2026-29202

On 2026-05-07, cPanel disclosed CVE-2026-29202, describing a Perl code injection issue in the create_user API call related to the plugin parameter. cPanel says fixed builds are available for affected cPanel & WHM branches, WP Squared 11.136.1.11 and later, and a direct 11.110.0.116 update for CentOS 6 or CloudLinux 6 systems. Administrators should prioritize upgrading any affected systems and verify that [truncated]

Review cPanel CVE published 2026-05-07

CVE-2026-29201

cPanel released a vendor security update for all supported cPanel & WHM versions that includes a fix for CVE-2026-29201, an arbitrary file read issue in the LOADFEATUREFILE adminbin call. The same update also addresses two additional vulnerabilities in cPanel & WHM, but this debrief focuses on the file-read issue tracked as CVE-2026-29201.

Review cPanel CVE published 2026-05-05

CVE-2026-40687

cPanel’s advisory groups CVE-2026-40684 through CVE-2026-40687 and says the underlying Exim issues affect versions prior to 4.99.2. cPanel has already released updated cpanel-exim 4.99.2 in patched cPanel/WHM builds, and administrators are advised to upgrade promptly. The source does not include exploit details, impact specifics, or a CVSS score for CVE-2026-40687.

Review cPanel CVE published 2026-05-05

CVE-2026-40686

cPanel’s advisory groups CVE-2026-40686 with three related Exim issues and says the fix is already available in updated cPanel/WHM builds. The vendor notes that Exim versions prior to 4.99.2 are affected and that upgrading cPanel/WHM to a patched release updates cpanel-exim to 4.99.2. The advisory does not provide separate technical details for CVE-2026-40686 by itself, so the most reliable defensive take [truncated]

Review cPanel CVE published 2026-05-05

CVE-2026-40685

cPanel’s advisory groups CVE-2026-40685 with three related Exim issues and states that versions of Exim prior to 4.99.2 are affected. For cPanel/WHM customers, the vendor says a patched Exim package is already available in specific builds, so the practical response is to move to the fixed cPanel/WHM release rather than waiting for a separate standalone remediation note.

Review cPanel CVE published 2026-05-05

CVE-2026-40684

cPanel’s advisory says Exim vulnerabilities affecting versions prior to 4.99.2 are fixed in updated cpanel-exim packages delivered through specific cPanel/WHM builds. Administrators running affected cPanel/WHM versions should upgrade to a patched release as soon as practical.

Review cPanel CVE published 2026-05-05

CVE-2026-24072

CVE-2026-24072 is a privilege-escalation issue in Apache HTTP Server that cPanel says affects version 2.4.66 and earlier. The vendor summary says local .htaccess authors may be able to read files with the privileges of the httpd user. Apache HTTP Server 2.4.67 is identified as the fixed release.

HIGH cPanel CVE published 2026-05-04

CVE-2026-23918

CVE-2026-23918 is a vendor-confirmed remote code execution issue called out in cPanel’s EasyApache 4 25.57 release notes. The advisory says ea-apache24 was updated to 2.4.67 to address 11 CVEs, including this one in mod_http2. For cPanel/WHM environments that use EasyApache 4, this is a high-priority security update because the affected component sits in the Apache package stack and the vendor characteriz [truncated]

MEDIUM cPanel CVE published 2026-04-02

CVE-2026-34830

cPanel’s EasyApache 4 25.53 release includes a security update for ea-ruby27-rubygem-rack that addresses CVE-2026-34830. The vendor notice does not provide additional vulnerability details in the supplied corpus, but it does confirm that affected EasyApache 4 package users should move to the updated release.