ZeroHour

CVE-2026-29205

CVSS 3.1
8.6 high
EPSS
8%p95
Published
()
Modified
Description

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Vendors
cpanel
Products
cpanel, wp squared, whm
Weakness
CWE-250
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

In the news