CVE-2026-29203Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home directory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 32 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 21 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 10 mentions (2026-05-10); latest day: 1
  • 32 total mentions across 7 days

Deep dive

Activity timeline32 mentions / 7d
035810Mentions · 2026-05-08: 4Mentions · 2026-05-09: 6Mentions · 2026-05-10: 10Mentions · 2026-05-11: 5Mentions · 2026-05-12: 5Mentions · 2026-05-21: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-05-09: 4Patch / Workaround · 2026-05-10: 7Patch / Workaround · 2026-05-11: 4Patch / Workaround · 2026-06-08: 1Technical Details · 2026-05-09: 5Technical Details · 2026-05-10: 8Technical Details · 2026-05-11: 4Technical Details · 2026-05-12: 3Technical Details · 2026-05-21: 105-0805-0905-1005-1105-1205-2106-08
Signal classification3 categories
Patch
1959.4%
Disclosure
1134.4%
General
26.3%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-05-084
Disclosure1Patch3
2026-05-096
Disclosure2Patch4
2026-05-1010
Disclosure3Patch7
2026-05-115
Disclosure1Patch4
2026-05-125
Disclosure4General1
2026-05-211
General1
2026-06-081
Patch1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Patch

    ⚠️ New cPanel and WHM Vulnerabilities Enable Code Execution, DoS Attacks Source: https://cybersecuritynews.com/cpanel-and-whm-flaws/ cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection, and denial-of-service (DoS) attacks, making immediate patching essential for hosting providers and server administrators. #cybersecuritynews

    Post summary

    The advisory informs that three critical CVEs (CVE‑2026‑29201/29202/29203) affecting cPanel/WHM have been patched, describing the flaws as arbitrary file reads, Perl injection, and DoS, and urges immediate patching.

    66752366124.0K
    68.9K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    Two of the three flaws are CVSS 8.8 — near-critical. • CVE-2026-29202 → arbitrary Perl code execution just by tweaking a “plugin” parameter • CVE-2026-29203 → unsafe symlink lets attackers chmod any file (DoS or privilege escalation) (No wild exploits on these three… yet.) If you run cPanel/WHM → update to 11.136.0.9+ right now.

    Post summary

    The post discloses two near-critical CVEs affecting cPanel/WHM, details their technical impact, and urges an immediate update to version 11.136.0.9+ to patch the flaws.

    64131443331.7K
    1.9M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    تذكرون ثغره (cPanel) (CVE-2026-41940) الي اكتشفت قبل اسبوع ؟ اكتشفت 3 ثغرات أمنية جديده و خطيرة. أخطر هذي الثغرات تعطي المهاجم صلاحيات لتنفيذ أوامر و اكواد على السيرفر. ⚙️ تفاصيل الثغرات الجديدة: الثغرة الأولى (CVE-2026-29201): خلل (Path Traversal) في مسار (LOADFEATUREFILE). الثغرة تسمح للمخترق بقراءة أي ملف على السيرفر، وهذا يشمل ملفات الإعدادات الحساسة، كلمات المرور، والمفاتيح الخاصة. الثغرة الثانية والأخطر (CVE-2026-29202): ثغرة تنفيذ أوامر عن بعد (RCE) في واجهة (create_user API). المخترق يقدر يرسل كود (Perl) خبيث وينفذه مباشرة على السيرفر. الثغرة الثالثة (CVE-2026-29203): تعامل غير آمن مع الروابط الرمزية (Symlinks). الثغرة تسمح للمستخدم بتغيير صلاحيات (chmod) لأي ملف على النظام، والنتيجة المحتملة هي إيقاف الخدمات (DoS) أو استغلاله لتنفيذ هجوم رفع الصلاحيات .

    Post summary

    The post announces three new cPanel vulnerabilities (CVE‑2026‑29201, 29202, 29203) with technical details covering path traversal, remote code execution, and symlink exploitation.

    19075335.9K
    50.0K followersView on X
  • محمد الربيعي@1ms25
    Patch

    [Important] cPanel & WHM Security Update CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 الله يعينكم ويعين كل مسؤول عن السيرفرات https://t.co/bDMsJZ0eXC

    Post summary

    The tweet announces that cPanel & WHM have released a security update for CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, urging administrators to apply the patches.

    010711.6K
    18.1K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-29202 & CVE-2026-29203: Two vulnerabilities in cPanel, 8.8 rating 🔥 The first vulnerability in cPanel allows an attacker to execute arbitrary commands directly on the server via Perl injection (CVE-2026-29202). The second one (CVE-2026-29203) leads to denial of service and possible privilege escalation. 👉 https://nt.ls/2en2n

    Post summary

    Two newly disclosed cPanel vulnerabilities—CVE-2026-29202 allows arbitrary command execution via Perl injection, while CVE-2026-29203 can cause denial of service and potential privilege escalation.

    10043730
    7.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos cPanel ❗ CVE-2026-29203 ❗ CVE-2026-29202 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cpanel/ https://t.co/eGnPYWt4vl

    Post summary

    The post lists two CVE identifiers for cPanel products and directs readers to a link for more details, lacking specific technical or exploit information.

    01011148
    6.7K followersView on X
  • Tre B@trerbbb
    Patch

    cpanel patched 3 bugs on May 8: CVE-2026-29201 (arbitrary file read), CVE-2026-29202 (perl code injection), CVE-2026-29203 (DoS). if you operate shared hosting, WHM is on every box. patch and audit Perl handlers. #cPanel

    Post summary

    cPanel reports patching three CVEs and advises admins to audit Perl handlers; no evidence of active exploitation or PoC.

    01020105
    17 followersView on X
  • Gustavo Gallas@ggallas
    Patch

    cPanel just released its second emergency patch in 10 days. CVE-2026-29202: arbitrary Perl code execution (CVSS 8.8) CVE-2026-29203: privilege escalation via symlink (CVSS 8.8) CVE-2026-29201: arbitrary file read If you run cPanel/WHM, run this now: /scripts/upcp Full breakdown 👇 https://www.copahost.com/blog/cpanels-black-week-three-new-vulnerabilities-patched-after-ransomware-attack-on-44000-servers/ #CyberSecurity #sysadmin #cpanel

    Post summary

    The post announces cPanel’s second emergency patch, details three high‑score CVEs and directs administrators to run /scripts/upcp to apply the fix.

    010102.6K
    372 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    Three cPanel WHM privilege escalation vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) allow file read, code execution, and symlink attacks. https://www.redsecuretech.co.uk/blog/post/cpanel-whm-privilege-escalation-vulnerabilities-get-patches/1168 #cPanel #WHM #CVE #PerlCodeExecution #SymlinkVulnerability #SorryRansomware #InfoSec https://t.co/irYEMsBcho

    Post summary

    Three cPanel WHM privilege escalation CVEs are announced with technical details, and a patch is referenced via the provided blog link.

    0101078
    48 followersView on X
  • Bendigo Aerial@BendigoAerial
    Patch

    🚨 cPanel/WHM Security Alert Three new vulnerabilities CVE-2026-29201 CVE-2026-29202 CVE-2026-29203 cPanel has issued a preemptive advisory. Details are limited until patches drop (today ~12pm EST), but they affect multiple supported versions. Update ASAP Check your cPanel/WHM servers now and apply patches immediately when available! 🔒

    Post summary

    cPanel has issued a pre‑emptive advisory for three CVEs, urging administrators to apply forthcoming patches as soon as they are released.

    00020203
    537 followersView on X
  • WebTuga - Alojamento Web@webtugahosting
    Disclosure

    🚨 cPanel & WHM anunciou novas vulnerabilidades: ▪️ CVE-2026-29201 ▪️ CVE-2026-29202 ▪️ CVE-2026-29203 +Info: https://status.wt.pt/vulnerabilidades-cpanel-whm-cve-2026-29201-cve-2026-29202-cve-2026-29203/ https://t.co/9octF8BhCd

    Post summary

    cPanel and WHM have announced three new CVEs, but no additional technical details, exploits, or mitigation steps are provided.

    01010197
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Key Details: CVE Numbers: CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 Patch Release: May 8, 2026, 12:00 EST Update Method: Automated tier-based distribution through cPanel's update mechanism; manual execution via /scripts/upcp for pinned or disabled auto-update servers…

    Post summary

    The announcement focuses on the upcoming patch release for CVE-2026‑29201, 29202, and 29203, detailing the distribution method via cPanel.

    1000027
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    • CVE-2026-29202 → arbitrary Perl code execution just by tweaking a “plugin” parameter • CVE-2026-29203 → unsafe symlink lets attackers chmod any file (DoS or privilege escalation)

    Post summary

    The post announces two new vulnerabilities: CVE-2026-29202 permits arbitrary Perl code execution through a parameter tweak, while CVE-2026-29203 enables attackers to change file permissions via an unsafe symlink, potentially causing DoS or privilege escalation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-29202: Two of the three flaws are CVSS 8.8 — near-critical. • CVE-2026-29202 → arbitrary Perl code execution just by tweaking a “plugin” parameter • CVE-2026-29203 → unsafe symlink lets attackers chmod any file (DoS or privilege escalation) (No wild exploits on…

    Post summary

    The post discloses that CVE-2026-29202 enables arbitrary Perl code execution by manipulating a plugin parameter and CVE-2026-29203 allows attackers to chmod any file via an unsafe symlink, both rated near-critical CVSS 8.8, with no PoC, exploit, patch, or active exploitation mention.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web

    Post summary

    cPanel has announced the disclosure of three critical vulnerabilities—CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203—affecting its widely deployed cPanel & WHM web interface.

    1000049
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-29201: ⚠️ New cPanel and WHM Vulnerabilities Enable Code Execution, DoS Attacks Source: cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed…

    Post summary

    cPanel announced three new critical vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) that allow code execution and DoS attacks on its widely deployed platform.

    1000047
    210 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🐞cPanel patched 3 serious flaws; CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The bugs could allow file reads, arbitrary Perl code execution, privilege escalation, and DoS attacks on WHM/cPanel servers. Read more: https://thecyberedition.com/cpanel-flaws-let-attackers-execute-code-and-escalate-privileges/ #cPanel #CyberSecurity

    Post summary

    cPanel has released patches for CVE‑2026‑29201, 29202, and 29203, addressing potential file reads, arbitrary code execution, privilege escalation, and DoS vulnerabilities, with no evidence of active exploitation or PoC.

    0001069
    728 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - cPanel Nova Symlink Privilege Escalation (CVE-2026-29203) A vulnerability in the cPanel Nova plugin allows authenticated attackers to abuse symlink handling during chmod operations to modify permissions on arbitrary system files or directories. Successful exploitation may lead to local privilege escalation or denial-of-service conditions by placing crafted symlinks in user-controlled paths. 👉Affected: cPanel & WHM Nova Plugin | Upgrade to May 08, 2026 security update versions

    Post summary

    CVE-2026-29203 exposes a symlink handling flaw in cPanel Nova that lets authenticated users modify system file permissions, causing privilege escalation or denial of service; the issue is fixed by the May 8, 2026 update.

    0001092
    176 followersView on X
  • Vivio Support@VivioSupport
    Patch

    Today, our team worked to apply new WHM/cPanel updates that came out at 9:00am PST. All but a few systems which are scheduled for later today have had the patch installed. The CVE IDs are CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203

    Post summary

    The team applied WHM/cPanel updates to address CVE‑2026‑29201, CVE‑2026‑29202, and CVE‑2026‑29203, indicating a patch deployment.

    00010136
    247 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-29203: cPanel & WHM Unsafe Symlink Handling - What It Means for Your Business and How to Respond https://hubs.li/Q04hvzNz0

    Post summary

    The information provides a headline about CVE-2026-29203, mentions the vulnerability type (unsafe symlink handling), but offers no concrete evidence of PoC, exploit, active exploitation, patch, or debunking claim.

    0000044
    31 followersView on X

Explore more