This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-32991
It was found that a low-privilege team user (role=default) can escalate to the owner account's full capabilities through the use of certain UAPI modules.
Action Taken
Our security team acted ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-32992
It was found that SSL verification was not fully enforced in the DNS Cluster system, which could allow for a malicious server to man-in-the-middle the request and capture credentials.
Action ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-29206
It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries.
Action Taken
Our security team acted immediately ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-29205
Through a combination of incorrect dropping of privileges and insufficient path filtering, it was possible to read arbitrary files via certain cpdavd endpoints.
Action Taken
Our security team ...
Continue reading