CVE-2026-29205: High severity Cpanel Cpanel vulnerability
Published May 13, 2026
·Updated
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Affected Software
14 affected components
Cpanel Cpanel>=120.0.0<124.0.38
Cpanel Cpanel>=126.0.0<126.0.59
Cpanel Cpanel>=130.0.0<130.0.23
Cpanel Cpanel>=130.0.23<130.0.23
Cpanel Cpanel>=132.0.0<132.0.32
Cpanel Cpanel>=134.0.0<134.0.26
Cpanel Cpanel>=136.0.0<136.0.10
Cpanel Wp Squared Wordpress>=120.1.0<136.1.12
Cpanel WHM>=120.0.0<124.0.38
Cpanel WHM>=126.0.0<126.0.59
Cpanel WHM>=130.0.0<130.0.23
Cpanel WHM>=132.0.0<132.0.32
Cpanel WHM>=134.0.0<134.0.26
Cpanel WHM>=136.0.0<136.0.10
Remediation
Event History
May 13, 2026
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-29205?
The severity of CVE-2026-29205 is rated high with a score of 8.6.
2
What vulnerabilities are associated with CVE-2026-29205?
CVE-2026-29205 involves incorrect privilege management and insufficient path filtering that allows arbitrary file reading on the server.
3
How do I fix CVE-2026-29205?
To mitigate CVE-2026-29205, apply the latest security updates from cPanel that address the identified vulnerabilities.
4
What types of attacks does CVE-2026-29205 facilitate?
CVE-2026-29205 facilitates the unauthorized reading of arbitrary files on the server, potentially exposing sensitive information.
5
Who is affected by CVE-2026-29205?
CVE-2026-29205 affects cPanel users utilizing the cpdavd attachment download endpoints.