Executive brief
cPanel, a widely used web hosting control panel, is vulnerable to a security flaw that could allow attackers to intercept sensitive information. By manipulating how the server processes web requests, an attacker could potentially capture user credentials. This could lead to unauthorized access to hosting accounts and the websites they manage.
Technical details
An HTTP Request Smuggling vulnerability (CWE-444) exists in WebPros cPanel and WP Squared due to inconsistent interpretation of HTTP requests between front-end and back-end systems. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests that are parsed differently by the proxy and the backend server. This allows the attacker to 'smuggle' a request into the next user's connection, potentially leading to the disclosure of sensitive information such as session cookies or login credentials. The vulnerability is addressed in various security releases including cPanel version 11.137.9999.98 and WP Squared 11.138.1.6.
Affected products
- WebPros cPanel < 11.110.0.137, < 11.118.0.71, < 11.126.0.78, < 11.134.0.48, < 11.136.0.32, < 11.137.9999.99
- WebPros WP Squared < 11.138.1.6
Timeline
- 2026-07-29: patched: Targeted Security Release 137.9999.98 published
- 2026-07-31: disclosed: CVE published to NVD via HackerOne