Vulnerabilities
Patch Now: New cPanel/WHM Vulnerabilities Enable Arbitrary Code Execution and Privilege Escalation
Cyber RTMay 11, 20263 min read

cPanel has issued updates to fix three vulnerabilities in cPanel and Web Host Manager (WHM), which could lead to privilege escalation, code execution, and denial-of-service. The vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, have been patched in various versions. Users are advised to update to the latest versions for protection. No exploitation has been reported, but a recent critical flaw was weaponized.
cPanel has issued updates to fix three significant vulnerabilities in its cPanel and Web Host Manager (WHM) software. These vulnerabilities, if exploited, could lead to privilege escalation, code execution, and denial-of-service attacks. The updates are crucial for maintaining the security and integrity of systems using these platforms.
The first vulnerability, identified as CVE-2026-29201, has a CVSS score of 4.3. It involves insufficient input validation of the feature file name in the "feature::LOADFEATUREFILE" adminbin call, which could potentially allow an attacker to read arbitrary files. This vulnerability, while not the most severe, still poses a risk to system security.
The second vulnerability, CVE-2026-29202, is more severe with a CVSS score of 8.8. It involves insufficient input validation of the "plugin" parameter in the "create_user API" call. This flaw could enable the execution of arbitrary Perl code on behalf of an authenticated system user, posing a significant threat to system integrity and security.
The third vulnerability, CVE-2026-29203, also has a CVSS score of 8.8. It involves unsafe symlink handling, which allows users to modify access permissions of arbitrary files using chmod. This could result in denial-of-service attacks or even privilege escalation, making it a critical issue that needs immediate attention.
To address these vulnerabilities, cPanel has released patches across multiple versions of cPanel and WHM. The patched versions include 11.136.0.9 and higher, among others, ensuring that users have a wide range of options for updating their systems to a secure state. Additionally, WP Squared has been updated to version 11.136.1.10 and higher.
For users still operating on CentOS 6 or CloudLinux 6, cPanel has provided a direct update to version 110.0.114. This ensures that even those on older systems can maintain a secure environment. Users are strongly advised to update to the latest versions to protect against potential exploits.
Although there is currently no evidence that these vulnerabilities have been exploited in the wild, the disclosure is timely. It follows closely on the heels of another critical flaw (CVE-2026-41940) in the product that was recently exploited as a zero-day vulnerability to deliver Mirai botnet variants and a ransomware strain called Sorry.
For ongoing updates and exclusive content, readers are encouraged to follow cPanel on platforms like Google News, Twitter, and LinkedIn. Staying informed about such vulnerabilities and updates is crucial for maintaining robust cybersecurity defenses.


