Critical cPanel Vulnerabilities Let Attackers Access System Resources
Key Takeaways Multiple critical vulnerabilities have been discovered in cPanel and WebHost Manager (WHM), posing significant risks to web hosting environments. The most severe flaw, CVE-2026-29202,...
Key Takeaways
- Multiple critical vulnerabilities have been discovered in cPanel and WebHost Manager (WHM), posing significant risks to web hosting environments.
- The most severe flaw, CVE-2026-29202, allows for arbitrary Perl code execution with system user permissions, carrying a CVSS score of 8.8.
- Other vulnerabilities include arbitrary file reads (CVE-2026-29201) and denial-of-service conditions.
- Patches are available for affected cPanel versions, and immediate updates are strongly recommended.
A series of critical security vulnerabilities affecting cPanel and WebHost Manager (WHM) has prompted an urgent call for web hosting administrators worldwide to implement immediate patching. These newly disclosed flaws could grant unauthenticated access to sensitive system resources, potentially leading to a complete compromise of web servers.
Table Of Content
Recent security bulletins from cPanel highlight several high-severity issues that present a substantial risk, particularly within shared hosting ecosystems. Threat actors are actively scrutinizing these vulnerabilities for potential exploitation.
Analysis of the cPanel Vulnerabilities
Among the recently addressed vulnerabilities, one stands out with a critical CVSS score of 9.8, indicating extreme severity. Other serious bugs could facilitate denial-of-service (DoS) attacks and various forms of account abuse.
Specific Vulnerabilities Detailed
One notable threat is CVE-2026-29202, rated with a CVSS score of 8.8. This flaw originates from insufficient input validation of the “plugin” parameter during a “create_user” API call. Successful exploitation could allow an attacker to execute arbitrary Perl code with the system permissions of an already authenticated account’s system user.
Another recently patched vulnerability, CVE-2026-29201, permits arbitrary file reads. This issue stems from inadequate validation of feature file names, potentially exposing underlying server configurations to unauthorized individuals.
Broader Linux Ecosystem Concerns
The security posture of Linux-based hosting servers is further complicated by concurrent vulnerabilities in underlying infrastructure software. On May 7, 2026, researchers unveiled “Dirty Frag,” tracked as CVE-2026-43284 and CVE-2026-43500. This local privilege escalation flaw resides within the Linux kernel’s page cache. Discovered by independent researcher Hyunwoo Kim, “Dirty Frag” bears resemblance to the notorious 2022 Dirty Pipe bug, enabling a low-level local user to effortlessly gain full root administrative control.
Moreover, email services frequently bundled with many hosting servers face significant risks from the Exim vulnerability CVE-2026-40684. This medium-severity flaw allows attackers to trigger denial-of-service conditions by providing malformed DNS data in PTR records, impacting systems utilizing musl libc.
cPanel has released updates that mitigate these critical pathways to code execution and privilege escalation across multiple version branches, including systems running versions 11.136.0.8 and earlier.
What You Should Do
- Immediate Patching: System administrators must prioritize updating cPanel, WHM, and WP Squared installations to the latest available releases without delay.
- Audit Access Logs: Security teams should promptly audit server access logs for any signs of unauthorized API calls or unusual local file reads, which could indicate active exploitation.
- Stay Informed: Continuously monitor cPanel’s security advisories and the broader cybersecurity landscape for new threats and mitigation strategies.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.