CVE-2026-29202Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 36 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 24 signals
  • Disclosure: 14 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 12 mentions (2026-05-10); latest day: 1
  • 36 total mentions across 7 days

Deep dive

Activity timeline36 mentions / 7d
036912Mentions · 2026-05-08: 4Mentions · 2026-05-09: 6Mentions · 2026-05-10: 12Mentions · 2026-05-11: 6Mentions · 2026-05-12: 6Mentions · 2026-05-14: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-05-09: 4Patch / Workaround · 2026-05-10: 7Patch / Workaround · 2026-05-11: 4Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-05-09: 5Technical Details · 2026-05-10: 11Technical Details · 2026-05-11: 4Technical Details · 2026-05-12: 3Technical Details · 2026-05-14: 105-0805-0905-1005-1105-1205-1406-08
Signal classification3 categories
Patch
2158.3%
Disclosure
1438.9%
General
12.8%
Referenced assets18 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-084
Disclosure1Patch3
2026-05-096
Disclosure2Patch4
2026-05-1012
Disclosure5Patch7
2026-05-116
Disclosure1General1Patch4
2026-05-126
Disclosure5Patch1
2026-05-141
Patch1
2026-06-081
Patch1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Patch

    ⚠️ New cPanel and WHM Vulnerabilities Enable Code Execution, DoS Attacks Source: https://cybersecuritynews.com/cpanel-and-whm-flaws/ cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection, and denial-of-service (DoS) attacks, making immediate patching essential for hosting providers and server administrators. #cybersecuritynews

    Post summary

    cPanel disclosed three critical CVEs (CVE‑2026‑29201‑29203) that allow arbitrary file reads, Perl code injection, and DoS; patches were released on May 8 2026, so administrators should apply them immediately.

    66752366124.0K
    68.9K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    Two of the three flaws are CVSS 8.8 — near-critical. • CVE-2026-29202 → arbitrary Perl code execution just by tweaking a “plugin” parameter • CVE-2026-29203 → unsafe symlink lets attackers chmod any file (DoS or privilege escalation) (No wild exploits on these three… yet.) If you run cPanel/WHM → update to 11.136.0.9+ right now.

    Post summary

    The post announces two high‑severity CVEs and recommends applying the cPanel/WHM patch 11.136.0.9+ to remediate them.

    64131443331.7K
    1.9M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    تذكرون ثغره (cPanel) (CVE-2026-41940) الي اكتشفت قبل اسبوع ؟ اكتشفت 3 ثغرات أمنية جديده و خطيرة. أخطر هذي الثغرات تعطي المهاجم صلاحيات لتنفيذ أوامر و اكواد على السيرفر. ⚙️ تفاصيل الثغرات الجديدة: الثغرة الأولى (CVE-2026-29201): خلل (Path Traversal) في مسار (LOADFEATUREFILE). الثغرة تسمح للمخترق بقراءة أي ملف على السيرفر، وهذا يشمل ملفات الإعدادات الحساسة، كلمات المرور، والمفاتيح الخاصة. الثغرة الثانية والأخطر (CVE-2026-29202): ثغرة تنفيذ أوامر عن بعد (RCE) في واجهة (create_user API). المخترق يقدر يرسل كود (Perl) خبيث وينفذه مباشرة على السيرفر. الثغرة الثالثة (CVE-2026-29203): تعامل غير آمن مع الروابط الرمزية (Symlinks). الثغرة تسمح للمستخدم بتغيير صلاحيات (chmod) لأي ملف على النظام، والنتيجة المحتملة هي إيقاف الخدمات (DoS) أو استغلاله لتنفيذ هجوم رفع الصلاحيات .

    Post summary

    The post announces three newly discovered cPanel vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) with details on their types and potential impact, but no PoC, exploit code, or evidence of active exploitation is provided.

    19075335.9K
    50.0K followersView on X
  • محمد الربيعي@1ms25
    Patch

    [Important] cPanel & WHM Security Update CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 الله يعينكم ويعين كل مسؤول عن السيرفرات https://t.co/bDMsJZ0eXC

    Post summary

    The tweet announces a cPanel and WHM security update addressing CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, indicating that patches have been released for these vulnerabilities.

    010711.6K
    18.1K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-29202 & CVE-2026-29203: Two vulnerabilities in cPanel, 8.8 rating 🔥 The first vulnerability in cPanel allows an attacker to execute arbitrary commands directly on the server via Perl injection (CVE-2026-29202). The second one (CVE-2026-29203) leads to denial of service and possible privilege escalation. 👉 https://nt.ls/2en2n

    Post summary

    CVE‑2026‑29202 permits arbitrary command execution in cPanel through Perl injection, while CVE‑2026‑29203 can cause denial‑of‑service and potential privilege escalation; no exploits, patches, or active exploitation were reported.

    10043730
    7.6K followersView on X
  • Cybernorse@Cybernorseab
    Patch

    @TheHackersNews cPanel CVSS 8.8 flaws (CVE-2026-29202-3) enable Perl code injection & privilege escalation via symlink. Update to 11.136.0.9+ immediately to prevent remote execution and DoS. #Cybernorse

    Post summary

    The post highlights cPanel CVE-2026-29202-3, detailing Perl code injection and privilege escalation via symlink, and urges users to update to version 11.136.0.9+ to prevent remote execution and DoS.

    01031227
    8 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-41940 2 - CVE-2026-3854 3 - CVE-2008-0166 4 - CVE-2026-7482 5 - CVE-2026-29202 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without providing technical details, PoC information, or evidence of exploitation.

    00031213
    1.7K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos cPanel ❗ CVE-2026-29203 ❗ CVE-2026-29202 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cpanel/ https://t.co/eGnPYWt4vl

    Post summary

    The tweet announces two cPanel vulnerabilities (CVE-2026-29203 and CVE-2026-29202) and provides links for more information, but offers no details on technical aspects, PoCs, or patches.

    01011148
    6.7K followersView on X
  • Tre B@trerbbb
    Patch

    cpanel patched 3 bugs on May 8: CVE-2026-29201 (arbitrary file read), CVE-2026-29202 (perl code injection), CVE-2026-29203 (DoS). if you operate shared hosting, WHM is on every box. patch and audit Perl handlers. #cPanel

    Post summary

    cPanel released patches for CVE‑2026‑29201, CVE‑2026‑29202, and CVE‑2026‑29203, covering arbitrary file read, perl code injection, and DoS, with a recommendation to audit Perl handlers.

    01020105
    17 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - cPanel WHM Authenticated RCE (CVE-2026-29202) Insufficient input validation in the plugin parameter of the "create_user" plugin allows an already authenticated attacker to execute arbitrary Perl code on behalf of the system user. 👉 Leads to full host compromise via RCE

    Post summary

    Disclosed a high-severity cPanel WHM authenticated RCE (CVE-2026-29202) permitting arbitrary Perl execution and full host compromise.

    00020157
    176 followersView on X
  • Gustavo Gallas@ggallas
    Patch

    cPanel just released its second emergency patch in 10 days. CVE-2026-29202: arbitrary Perl code execution (CVSS 8.8) CVE-2026-29203: privilege escalation via symlink (CVSS 8.8) CVE-2026-29201: arbitrary file read If you run cPanel/WHM, run this now: /scripts/upcp Full breakdown 👇 https://www.copahost.com/blog/cpanels-black-week-three-new-vulnerabilities-patched-after-ransomware-attack-on-44000-servers/ #CyberSecurity #sysadmin #cpanel

    Post summary

    The text announces cPanel’s second emergency patch, lists the CVEs with basic technical details, and provides instructions to apply the patch.

    010102.6K
    372 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    Three cPanel WHM privilege escalation vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) allow file read, code execution, and symlink attacks. https://www.redsecuretech.co.uk/blog/post/cpanel-whm-privilege-escalation-vulnerabilities-get-patches/1168 #cPanel #WHM #CVE #PerlCodeExecution #SymlinkVulnerability #SorryRansomware #InfoSec https://t.co/irYEMsBcho

    Post summary

    Three cPanel WHM privilege‑escalation CVEs (29201‑29203) enable file read, code execution, and symlink attacks, and patches are available as noted in the linked article.

    0101078
    48 followersView on X
  • Bendigo Aerial@BendigoAerial
    Patch

    🚨 cPanel/WHM Security Alert Three new vulnerabilities CVE-2026-29201 CVE-2026-29202 CVE-2026-29203 cPanel has issued a preemptive advisory. Details are limited until patches drop (today ~12pm EST), but they affect multiple supported versions. Update ASAP Check your cPanel/WHM servers now and apply patches immediately when available! 🔒

    Post summary

    The post announces three CVE vulnerabilities affecting cPanel/WHM, with a preemptive advisory urging organizations to apply forthcoming patches immediately.

    00020203
    537 followersView on X
  • WebTuga - Alojamento Web@webtugahosting
    Disclosure

    🚨 cPanel & WHM anunciou novas vulnerabilidades: ▪️ CVE-2026-29201 ▪️ CVE-2026-29202 ▪️ CVE-2026-29203 +Info: https://status.wt.pt/vulnerabilidades-cpanel-whm-cve-2026-29201-cve-2026-29202-cve-2026-29203/ https://t.co/9octF8BhCd

    Post summary

    cPanel & WHM announced three new CVEs (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) and provided a link for further details.

    01010197
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Key Details: CVE Numbers: CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 Patch Release: May 8, 2026, 12:00 EST Update Method: Automated tier-based distribution through cPanel's update mechanism; manual execution via /scripts/upcp for pinned or disabled auto-update servers…

    Post summary

    Patch release announced for CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 with automated and manual update options via cPanel.

    1000027
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    • CVE-2026-29202 → arbitrary Perl code execution just by tweaking a “plugin” parameter • CVE-2026-29203 → unsafe symlink lets attackers chmod any file (DoS or privilege escalation)

    Post summary

    The brief discloses two new CVEs: CVE-2026-29202 enables arbitrary Perl code execution by altering a plugin parameter, while CVE-2026-29203 allows attackers to chmod any file via an unsafe symlink, facilitating DoS or privilege escalation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-29202: Two of the three flaws are CVSS 8.8 — near-critical. • CVE-2026-29202 → arbitrary Perl code execution just by tweaking a “plugin” parameter • CVE-2026-29203 → unsafe symlink lets attackers chmod any file (DoS or privilege escalation) (No wild exploits on…

    Post summary

    The text highlights the disclosure of two high‑severity flaws, CVE‑2026‑29202 and CVE‑2026‑29203, with technical details but no PoC, exploit code, or patch information.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web

    Post summary

    cPanel announced the existence of three critical vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) affecting its cPanel and WHM web interfaces.

    1000049
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-29201: ⚠️ New cPanel and WHM Vulnerabilities Enable Code Execution, DoS Attacks Source: cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed…

    Post summary

    cPanel announced three new critical vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) that enable code execution and DoS attacks. No PoC, exploit, or patch details are provided.

    1000047
    210 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🐞cPanel patched 3 serious flaws; CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The bugs could allow file reads, arbitrary Perl code execution, privilege escalation, and DoS attacks on WHM/cPanel servers. Read more: https://thecyberedition.com/cpanel-flaws-let-attackers-execute-code-and-escalate-privileges/ #cPanel #CyberSecurity

    Post summary

    cPanel announced patches for CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, which could enable file reads, arbitrary Perl code execution, privilege escalation, and DoS attacks on WHM/cPanel servers. The article confirms patch availability but does not mention active exploitation or exploit code.

    0001069
    728 followersView on X

Explore more