Junglewise Threat Intelligence

CVE-2026-29205: Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment downloa

CVE-2026-29205 · Severity: high · CVSS 8.6 · Published 2026-05-13

Technologies: cPanel WP Squared. Vendors: cPanel.

Executive brief

cPanel & WHM, a widely used web hosting control panel, contains a security flaw in its file handling system. An attacker can exploit this to read sensitive files directly from the server without needing a password. This could lead to the exposure of configuration data, user credentials, or other private information stored on the hosting server.

Technical details

A vulnerability exists in the cpdavd component of cPanel & WHM, specifically within the attachment download endpoints. The flaw stems from a combination of execution with unnecessary privileges (CWE-250) and insufficient path filtering. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected endpoints to bypass directory restrictions. This allows for the unauthorized reading of arbitrary files on the server's filesystem. cPanel has released a security update to address this issue.

Affected products

  • cPanel cPanel & WHM

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats