CVE-2016-10826: High severity Cpanel Cpanel vulnerability
Published Aug 1, 2019
·Updated
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
Affected Software
3 affected components
Cpanel Cpanel>=11.50.0.4<11.50.5.2
Cpanel Cpanel>=11.52.0.5<11.52.4.1
Cpanel Cpanel>=11.54.0.0<11.54.0.20
Event History
Aug 1, 2019
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10826?
CVE-2016-10826 is classified as a medium severity vulnerability that allows attackers to bypass Two Factor Authentication.
2
How do I fix CVE-2016-10826?
To fix CVE-2016-10826, update your cPanel installation to version 55.9999.141 or later.
3
What versions of cPanel are affected by CVE-2016-10826?
CVE-2016-10826 affects cPanel versions prior to 55.9999.141, including 11.50.0.4 to 11.50.5.2, 11.52.0.5 to 11.52.4.1, and 11.54.0.0 to 11.54.0.20.
4
Is CVE-2016-10826 easy to exploit?
Yes, CVE-2016-10826 can be exploited relatively easily through DNS clustering requests.
5
What impact does CVE-2016-10826 have on user accounts?
CVE-2016-10826 can potentially compromise user accounts by bypassing the security of Two Factor Authentication.