Junglewise Threat Intelligence

CVE-2026-32992: SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture

CVE-2026-32992 · Severity: high · CVSS 8.2 · Published 2026-05-13

Technologies: cPanel WP Squared. Vendors: cPanel.

Executive brief

A security flaw in the cPanel DNS Cluster system allows for the interception of sensitive data. Because the system fails to verify SSL certificates, a malicious actor could position themselves between servers to steal login credentials. This could lead to unauthorized access to hosting infrastructure and the compromise of customer data.

Technical details

The cPanel DNS Cluster system suffers from improper certificate validation (CWE-295) because SSL verification is explicitly disabled during communication. This vulnerability allows a network-positioned attacker to perform a man-in-the-middle (MitM) attack without requiring any prior authentication or user interaction. By intercepting the unverified connection, the attacker can capture sensitive credentials transmitted between cluster nodes. The issue was addressed in the May 13, 2026, security update for cPanel & WHM.

Affected products

  • cPanel cPanel & WHM

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: patched
  • 2026-05-13: advisory

References

Related threats