Vulnerability Description
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cpanel | Cpanel | >= 120.0.0, < 124.0.38 |
| Cpanel | Wp Squared | >= 120.1.0, < 136.1.12 |
| Cpanel | Whm | >= 120.0.0, < 124.0.38 |
Related Weaknesses (CWE)
References
- https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-29PatchVendor Advisory
FAQ
What is CVE-2026-29205?
CVE-2026-29205 is a vulnerability with a CVSS score of 8.6 (HIGH). Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
How severe is CVE-2026-29205?
CVE-2026-29205 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29205?
Check the references section above for vendor advisories and patch information. Affected products include: Cpanel Cpanel, Cpanel Wp Squared, Cpanel Whm.