CVE-2020-26104: High severity cpanel vulnerability
Published Sep 25, 2020
·Updated
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
Affected Software
1 affected component
Cpanel Cpanel<88.0.3
Event History
Sep 25, 2020
CVE Published
via MITRE·05:42 AM
Data Sourced
via MITRE·05:42 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cPanel vulnerability?
The vulnerability ID for this cPanel vulnerability is CVE-2020-26104.
2
What is the severity of CVE-2020-26104?
The severity of CVE-2020-26104 is high with a CVSS score of 7.5.
3
What is the affected software version for CVE-2020-26104?
The affected software version for CVE-2020-26104 is cPanel before 88.0.3.
4
What is the CWE number for this vulnerability?
The CWE number for this vulnerability is CWE-922.
5
How can I fix the CVE-2020-26104 vulnerability?
To fix the CVE-2020-26104 vulnerability, update cPanel to version 88.0.3 or higher.