← Back

CVE-2025-66429

nvd nist
Published: Dec 11, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

Affected (3)

Products: Cpanel: Cpanel
1 product
Cpanel
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
From 110.0.0 to 126.0.37
From 128.0.1 to 130.0.16
From 132.0.0 to 132.0.4

References (2)

Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
Not Applicable

Timeline

No history available yet.