CVE-2026-29205Patch(cpanel / cpanel)

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cpanel cpanel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpanel
  • whm
  • wp_squared

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 25 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 15 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 10d ago at 5 mentions (2026-05-13); latest day: 1
  • 25 total mentions across 11 days

Affected systems

Vendors
Products
cpanelwhmwp_squared

Deep dive

Activity timeline25 mentions / 11d
01345Mentions · 2026-05-13: 5Mentions · 2026-05-14: 2Mentions · 2026-05-15: 2Mentions · 2026-05-18: 4Mentions · 2026-05-19: 4Mentions · 2026-05-20: 1Mentions · 2026-05-29: 1Mentions · 2026-06-13: 1Mentions · 2026-06-24: 3Mentions · 2026-07-12: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-20: 1Patch / Workaround · 2026-05-13: 4Patch / Workaround · 2026-05-14: 2Patch / Workaround · 2026-05-15: 2Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-06-24: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-18: 3Technical Details · 2026-05-19: 3Technical Details · 2026-05-20: 1Technical Details · 2026-06-13: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-12: 1Technical Details · 2026-08-19: 105-1305-1405-1505-1805-1905-2005-2906-1306-2407-1208-19
Signal classification4 categories
Patch
1352.0%
Disclosure
728.0%
General
312.0%
PoC
28.0%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-05-135
Disclosure1Patch4
2026-05-142
Patch2
2026-05-152
Patch2
2026-05-184
Disclosure1General1Patch1PoC1
2026-05-194
Disclosure2General1Patch1
2026-05-201
PoC1
2026-05-291
General1
2026-06-131
Disclosure1
2026-06-243
Patch3
2026-07-121
Disclosure1
2026-08-191
Disclosure1
Full discourse20 posts
  • Assetnote@assetnote
    PoC

    Our security research team discovered a pre-authentication arbitrary file read as root in cPanel (CVE-2026-29205) — a path traversal in cpdavd that we made exploitable by abusing Dovecot's + alias handling to create attacker-controlled directory names on disk. We've updated cpanel2shell-scanner to cover both issues. Writeup and tool in replies. 👇

    Post summary

    The security team uncovered a pre-auth arbitrary file read in cPanel, described its technical details, and released a writeup and scanner tool, but no active exploitation or patch is discussed.

    24111607526.8K
    10.5K followersView on X
  • shubs@infosec_au
    Patch

    cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. We made the call to not publish our research until a working patch is released. We are in touch with WebPro's security team.

    Post summary

    The post states that cPanel’s recent patch for CVE‑2026‑29205 is incomplete and that researchers will not publish until a complete patch is released, highlighting ongoing communication with the vendor.

    22171704124.5K
    58.8K followersView on X
  • Swissky@pentest_swissky
    Disclosure

    New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) - Shubham Shah, Adam Kues, Patrik Grobshäuser - @SLCyberSec https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205

    Post summary

    The text reports the announcement of a new CVE (2026‑29205) affecting cPanel, highlighting the “reading arbitrary files pre‑auth as root” vulnerability, but it contains no PoC, exploit details, patch information, or evidence of active exploitation.

    18020163.1K
    22.5K followersView on X
  • Densel@luckyhacker43
    Disclosure

    New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) 👾💥 👨‍💻 Searchlight Cyber 🔗 https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205 Join team 👉 https://t.me/luckyhacker43 https://t.co/1bDGKvkAiV

    Post summary

    The tweet announces the discovery of a pre‑authentication file read vulnerability (CVE‑2026‑29205) that allows root access in cPanel, providing a high‑confidence disclosure of the vulnerability type.

    010106546
    2.9K followersView on X
  • Assetnote@assetnote
    General

    https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205

    Post summary

    The text is simply a link to an article about CVE-2026-29205, with no explicit details on PoC, exploitation, or mitigation.

    140643.2K
    10.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    cPanel & WHM Patch 5 High-Severity Flaws, Including 8.6 Severity File Read and SQLi https://securityonline.info/cpanel-whm-security-patches-cve-2026-29205-file-read-sql-injection/

    Post summary

    The article announces the release of patches for five high‑severity cPanel/WHM vulnerabilities, highlighting a file read and SQL injection flaw (CVE‑2026‑29205).

    000101723
    12.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    cPanel / WHM'de yeni güvenlik açıkları duyuruldu. Henüz NVD'de görünmeyen bu açıklar için bugün TSİ 21:00 dan sonra patch çıkacak. İlgili saatten sonra /scripts/upcp --force yapmayı unutmayın. * CVE-2026-29205 * CVE-2026-29206 * CVE-2026-32991 * CVE-2026-32992 * CVE-2026-32993

    Post summary

    New cPanel/WHM CVEs announced; patches will drop after 21:00; run /scripts/upcp --force to update.

    10050285
    1.2K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    cPanel & WHMでまた深刻な脆弱性5件が修正。CVE-2026-29205、CVE-2026-32993、CVE-2026-32992、CVE-2026-29206、CVE-2026-32991。 https://securityonline.info/cpanel-whm-security-patches-cve-2026-29205-file-read-sql-injection/

    Post summary

    The text announces that cPanel & WHM have patched five severe vulnerabilities (CVE-2026-29205, 32993, 32992, 29206, 32991) and provides a link to the security patch details.

    00032886
    7.6K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) https://dlvr.it/TV4pj7 #cyber #threathunting #infosec

    Post summary

    The tweet announces CVE-2026-29205, a pre‑authentication arbitrary file read flaw in cPanel that allows root access, but provides no PoC, patch, or exploitation evidence.

    010121.5K
    57.5K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205

    Post summary

    A research article discloses a new pre‑authentication file‑read vulnerability in cPanel (CVE-2026-29205), providing limited technical details but no evidence of active exploitation, PoC, or patch.

    00012936
    158.6K followersView on X
  • Host TugaTech@hostuptime
    Patch

    ⚠️ Alerta: Vulnerabilidades críticas detetadas no cPanel (CVE-2026-29205 e outras). A atualização imediata é essencial para proteger os seus dados. Na Host TugaTech, a segurança está em primeiro lugar. Proteja o seu servidor https://host.tugatech.com.pt/ https://t.co/XgQQoQbiJ8

    Post summary

    The message alerts about critical cPanel CVEs and urges immediate patching, but provides no exploit details or technical depth.

    01010237
    245 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    cPanel announced via direct customer email and hosting provider forums that a coordinated security patch will deploy automatically at 13:00 UTC (1:00 PM EST) on May 13, 2026. The release addresses multiple HIGH-severity flaws: CVE-2026-29205 – (Details pending technical…

    Post summary

    The post announces that cPanel will automatically deploy a patch for CVE‑2026‑29205 on May 13, 2026; specific vulnerability details remain pending.

    1000034
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    cPanel & WHM is releasing an emergency security patch on May 13, 2026 at 1:00 PM EST addressing five HIGH-severity vulnerabilities (CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993) affecting versions 86 through 136. According to the vendor,…

    Post summary

    cPanel & WHM have issued an emergency patch for five high‑severity CVEs affecting versions 86‑136, highlighting an urgent remediation effort.

    1000031
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The Perfect Storm: cPanel & WHM May 13 Coordinated Release — Five HIGH CVEs, Zero Exploits (Yet). cPanel & WHM is releasing an emergency security patch on May 13, 2026 at 1:00 PM EST addressing five HIGH-severity vulnerabilities CVE-2026-29205, CVE-2026-29206,…

    Post summary

    The notice announces a scheduled patch for five high‑severity CVEs in cPanel & WHM, with no current exploits or PoC discussed.

    1000041
    295 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos cPanel ❗ CVE-2026-32993 ❗ CVE-2026-32992 ❗ CVE-2026-29205 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cpanel-2/ https://t.co/XKmd99xRP0

    Post summary

    The post lists three cPanel CVE identifiers and directs readers to external links for additional information.

    00010124
    6.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-2276 2 - CVE-2026-42945 3 - CVE-2026-20182 4 - CVE-2026-40369 5 - CVE-2026-29205 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top five trending CVEs, providing no additional details on exploitation, patches, or technical aspects.

    00010200
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    No login. No privileges. Read any file as root. CVE-2026-29205 - path traversal in cPanel's cpdavd, weaponized by abusing Dovecot's + alias handling to plant attacker-controlled directory names on disk. Pre-auth. Root. cPanel. A public scanner is already updated to find exposed hosts. http://vulntracker.io

    Post summary

    The passage discloses a pre-authenticated root-privilege path traversal flaw in cPanel’s cpdavd, outlining its weaponization method but offering no patch, PoC, or evidence of active exploitation.

    00001276
    653 followersView on X
  • N45HT@N45HTOfficial
    Disclosure

    New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) 👾💥​ 👨‍💻 Searchlight Cyber 🔗 https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205 https://t.co/wbI4S9lZZU

    Post summary

    Searchlight Cyber announces CVE-2026-29205, a pre‑authentication root file‑read vulnerability in cPanel, with technical details but no patch, exploit, or in‑the‑wild activity disclosed.

    01000176
    92 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability in #cPanel and #WHM. CVE-2026-29205 CVSS: 8.6. Incorrect privilege management and insufficient path filtering allow to read arbitrary files using the attachment download endpoint! More info: https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026 #Patch #Patch #Patch

    Post summary

    A critical cPanel and WHM vulnerability (CVE‑2026‑29205) is disclosed with CVSS 8.6, allowing arbitrary file reads via the attachment download endpoint, and a patch is available via cPanel’s support article.

    00001303
    7.2K followersView on X
  • Factoría Digital Hosting@factoriadigital
    Patch

    Actualizados los servidores de clientes a la ultima version de cPanel que ha salido hace 2h. Vulnerabilidades corregidas de riesgo ALTO: CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993.  No es necesaria ninguna acción. #seguridad #cPanel

    Post summary

    The latest cPanel update patches several high‑risk CVEs, and users are advised that no additional action is needed.

    00010116
    799 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appcpanelcpanel---
Appcpanelwhm---
Appcpanelwp_squared-wordpress-

Explore more