CVE-2021-26267: High severity cpanel vulnerability
Published Jan 26, 2021
·Updated
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
Affected Software
1 affected component
Cpanel Cpanel<92.0.9
Event History
Jan 26, 2021
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cPanel vulnerability?
The vulnerability ID for this cPanel vulnerability is CVE-2021-26267.
2
What is the severity of CVE-2021-26267?
The severity of CVE-2021-26267 is high with a CVSS score of 7.5.
3
What is the affected software version for CVE-2021-26267?
The affected software version for CVE-2021-26267 is cPanel before 92.0.9.
4
How does CVE-2021-26267 allow a MySQL user to bypass suspension?
CVE-2021-26267 allows a MySQL user with an old-style password hash to bypass suspension in cPanel before 92.0.9.
5
Where can I find more information about CVE-2021-26267?
You can find more information about CVE-2021-26267 in the cPanel version 92.0.9 change log: [https://docs.cpanel.net/changelogs/92-change-log/](https://docs.cpanel.net/changelogs/92-change-log/).