CVE-2020-26105: Critical severity cpanel vulnerability
Published Sep 25, 2020
·Updated
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
Affected Software
1 affected component
Cpanel Cpanel<88.0.3
Event History
Sep 25, 2020
CVE Published
via MITRE·05:42 AM
Data Sourced
via MITRE·05:42 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26105?
CVE-2020-26105 is a vulnerability in cPanel before version 88.0.3, where insecure chkservd test credentials are used on a templated virtual machine (VM).
2
How severe is CVE-2020-26105?
CVE-2020-26105 has a severity rating of 9.8, which is classified as critical.
3
How does CVE-2020-26105 affect cPanel?
CVE-2020-26105 affects cPanel versions prior to 88.0.3 and allows the use of insecure chkservd test credentials on a templated VM.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-26105?
CVE-2020-26105 is associated with CWE-287, which refers to an insecure dependency.
5
How can I fix CVE-2020-26105?
To fix CVE-2020-26105, you should update cPanel to version 88.0.3 or later, which addresses the issue.