First published: Thu Aug 01 2019(Updated: )
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=61.9999.55<62.0.42 | |
Cpanel Cpanel | >=67.9999.64<68.0.33 | |
Cpanel Cpanel | >=69.9999.122<70.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20926 has been classified as a local privilege escalation vulnerability, which can have significant impacts on affected systems.
To resolve CVE-2018-20926, upgrade to cPanel version 70.0.23 or later.
CVE-2018-20926 affects cPanel versions prior to 70.0.23, including versions 61.9999.55 to 62.0.42 and 67.9999.64 to 68.0.33.
Exploitation of CVE-2018-20926 can allow attackers to gain elevated privileges on the system.
Typically, a server reboot is not necessary after upgrading to a secure version to address CVE-2018-20926.