☀️ Summer New Offers are LIVE! → 🎁 Open our Offers Page & get exciting deals with flat upto 20-30% OFF on all products → 🚀 Boost your hosting with faster, secure & reliable services at DotShift → 🔥 Don’t miss limited-time summer discounts across hosting, VPS, reseller & more → 👉 Visit Now: https://dotshift.net/offers 🎉     
Login
Offers
⚠️ Critical Security Vulnerability

A vulnerability identified as CVE-2026-29205 affects the cpdavd service in cPanel & WHM versions 120 and higher.

📢 Additional Patch Released

On May 14, 2026, cPanel released an additional fix expanding upon the original patch from May 13, 2026. Administrators are strongly advised to update their servers again to ensure complete protection.

🔍 Vulnerability Overview

cPanel discovered that incorrect privilege dropping combined with insufficient path filtering inside certain cpdavd endpoints could allow arbitrary file reads.

Attackers may exploit this issue to access sensitive files on the server under specific conditions.

The vulnerability impacts systems running cPanel & WHM 120 and later.

🚨 Potential Impact

  • Arbitrary file read access
  • Exposure of sensitive configuration files
  • Credential disclosure risks
  • Potential privilege escalation paths
  • Unauthorized access to server information

📌 Affected Versions

cPanel & WHM 120 and higher

✅ Fully Patched Versions

11.124.0.40+
11.126.0.61+
11.130.0.25+
11.132.0.34+
11.134.0.28+
11.136.0.12+
WP Squared patched version:
11.136.1.15 and higher

🛠️ How to Update cPanel

Run the following command as root:

/scripts/upcp --force

Verify the installed version after updating:

/usr/local/cpanel/cpanel -V

🛡️ Temporary Mitigation

If you are unable to update immediately, block inbound access to the following ports at the firewall:

Port 2079
Port 2080

This mitigation should only be considered temporary until the server is fully updated.

🔒 Additional Security Fixes Included

CVE-2026-29206
CVE-2026-32991
CVE-2026-32992
CVE-2026-32993
🔒 Security Recommendation

Update all cPanel servers immediately and verify that older, partially patched builds are no longer in use.

⚠️ Final Security Warning:
Servers running outdated cPanel versions remain vulnerable to arbitrary file read attacks through cpdavd endpoints.