Junglewise Threat Intelligence

CVE-2026-29206: cPanel sqloptimizer SQL injection in utility script

CVE-2026-29206 · Severity: high · CVSS 8.1 · Published 2026-05-13

Technologies: cPanel WP Squared. Vendors: cPanel.

Executive brief

A security vulnerability has been identified in cPanel & WHM and WP Squared, popular web hosting control panels. The flaw exists in a utility script used for database optimization, which fails to properly clean data before processing it. If an attacker can trigger specific database logging conditions, they could execute unauthorized commands with administrative (root) privileges, potentially leading to full server compromise or data loss.

Technical details

A SQL injection vulnerability exists in the `sqloptimizer` utility script within cPanel & WHM and WP Squared. The root cause is insufficient sanitization of SQL queries processed by the script. When Slow Query logging is enabled, an attacker can craft malicious SQL statements that, when processed by the optimizer utility, execute with root-level privileges. While the attack vector is listed as network-based, it requires the 'Slow Query' logging precondition and some level of user interaction (UI:R) to trigger the script's execution on the malicious data. Successful exploitation allows for unauthorized data modification or service disruption. Patches have been released across multiple version branches.

Affected products

  • cPanel cPanel & WHM < 11.86.0.44, < 11.94.0.31, < 11.102.0.42, < 11.110.0.118, < 11.118.0.67, < 11.124.0.38, < 11.126.0.59, < 11.130.0.23, < 11.132.0.32, < 11.134.0.26, < 11.136.0.10
  • cPanel WP Squared < 11.136.1.12

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2026-05-13: patched

References

Related threats