CVE-2026-29205

EUVD-2026-30178
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.07%
Affected Products (NVD)
VendorProductVersion
cpanelcpanel
120.0.0 ≤
𝑥
< 124.0.38
cpanelcpanel
126.0.0 ≤
𝑥
< 126.0.59
cpanelcpanel
130.0.0 ≤
𝑥
< 130.0.23
cpanelcpanel
130.0.23 ≤
𝑥
< 130.0.23
cpanelcpanel
132.0.0 ≤
𝑥
< 132.0.32
cpanelcpanel
134.0.0 ≤
𝑥
< 134.0.26
cpanelcpanel
136.0.0 ≤
𝑥
< 136.0.10
cpanelwp_squared
120.1.0 ≤
𝑥
< 136.1.12
cpanelwhm
120.0.0 ≤
𝑥
< 124.0.38
cpanelwhm
126.0.0 ≤
𝑥
< 126.0.59
cpanelwhm
130.0.0 ≤
𝑥
< 130.0.23
cpanelwhm
132.0.0 ≤
𝑥
< 132.0.32
cpanelwhm
134.0.0 ≤
𝑥
< 134.0.26
cpanelwhm
136.0.0 ≤
𝑥
< 136.0.10
𝑥
= Vulnerable software versions