Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
References
| Link | Resource |
|---|---|
| https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29205-cPanel-WHM-WP2-Security-Update-May-13-2026 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2026-05-13 22:16
Updated : 2026-08-12 18:34
NVD link : CVE-2026-29205
Mitre link : CVE-2026-29205
CVE.ORG link : CVE-2026-29205
JSON object : View
Products Affected
cpanel
- whm
- wp_squared
- cpanel
CWE
CWE-250
Execution with Unnecessary Privileges
