Executive brief
cPanel & WHM, a widely used web hosting control panel, contains a security flaw in its file handling system. An attacker can exploit this to read sensitive files directly from the server without needing a password. This could lead to the exposure of configuration data, user credentials, or other private information stored on the hosting server.
Technical details
A vulnerability exists in the cpdavd component of cPanel & WHM, specifically within the attachment download endpoints. The flaw stems from a combination of execution with unnecessary privileges (CWE-250) and insufficient path filtering. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected endpoints to bypass directory restrictions. This allows for the unauthorized reading of arbitrary files on the server's filesystem. cPanel has released a security update to address this issue.
Affected products
- cPanel cPanel & WHM
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory