← Back

CVE-2026-29205

nvd nist
Published: May 13, 2026Modified: Aug 12, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Exploitability: 3.9 / Impact: 4.7
Source: support@hackerone.com (Secondary)

Description

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Affected (14)

3 products
Cpanel
Wp Squared
Whm
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
From 120.0.0 to 124.0.38
From 126.0.0 to 126.0.59
From 130.0.0 to 130.0.23
From 130.0.23 to 130.0.23
From 132.0.0 to 132.0.32
From 134.0.0 to 134.0.26
From 136.0.0 to 136.0.10
From 120.1.0 to 136.1.12
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Cpanel
From 120.0.0 to 124.0.38
From 126.0.0 to 126.0.59
From 130.0.0 to 130.0.23
From 132.0.0 to 132.0.32
From 134.0.0 to 134.0.26
From 136.0.0 to 136.0.10

Timeline

No history available yet.