CVE-2020-26107: High severity cpanel vulnerability
Published Sep 25, 2020
·Updated
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
Affected Software
1 affected component
Cpanel Cpanel<88.0.3
Event History
Sep 25, 2020
CVE Published
via MITRE·05:42 AM
Data Sourced
via MITRE·05:42 AM
Description
Frequently Asked Questions
1
What is CVE-2020-26107?
CVE-2020-26107 is a vulnerability in cPanel before version 88.0.3 that allows for the establishment of predictable PowerDNS API keys during an upgrade.
2
How severe is CVE-2020-26107?
CVE-2020-26107 has a severity rating of high, with a CVSS score of 7.5.
3
What is the affected software version for CVE-2020-26107?
The affected software version for CVE-2020-26107 is cPanel up to version 88.0.3.
4
How can I fix CVE-2020-26107?
To fix CVE-2020-26107, you should upgrade your cPanel to version 88.0.3 or newer.
5
Where can I find more information about CVE-2020-26107?
You can find more information about CVE-2020-26107 in the cPanel change log for version 88.0.3.