CVE-2020-26098: Critical severity cpanel vulnerability
Published Sep 25, 2020
·Updated
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
Affected Software
1 affected component
Cpanel Cpanel<88.0.3
Event History
Sep 25, 2020
CVE Published
via MITRE·05:43 AM
Data Sourced
via MITRE·05:43 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26098?
CVE-2020-26098 is a vulnerability in cPanel before version 88.0.3 that mishandles the Exim filter path, leading to remote code execution.
2
What is the severity of CVE-2020-26098?
CVE-2020-26098 has a severity rating of critical with a CVSS score of 9.8.
3
How does CVE-2020-26098 affect cPanel?
CVE-2020-26098 affects cPanel before version 88.0.3 by mishandling the Exim filter path, which can result in remote code execution.
4
How can I fix CVE-2020-26098?
To fix CVE-2020-26098, you should update to cPanel version 88.0.3 or above, as this vulnerability has been patched in that version.
5
Where can I find more information about CVE-2020-26098?
You can find more information about CVE-2020-26098 in the cPanel changelog at https://docs.cpanel.net/changelogs/88-change-log/