CVE-2026-29201 Details
Description
Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.
A vulnerability allowing arbitrary file read has been identified in cPanel and WHM WP2. The issue arises from insufficient input validation of the feature file name in the feature::LOADFEATUREFILE adminbin call. This vulnerability allows relative file paths to be passed as arguments, making arbitrary files world-readable.
Users can update to cPanel & WHM versions 11.136.0.9 and higher, 11.134.0.25 and higher, 11.132.0.31 and higher, 11.130.0.22 and higher, 11.126.0.58 and higher, 11.124.0.37 and higher, 11.118.0.66 and higher, 11.110.0.116 and higher, 11.110.0.117 and higher, 11.102.0.41 and higher, 11.94.0.30 and higher, or 11.86.0.43 and higher. For those on CentOS 6 or CloudLinux 6, cPanel v110.0.114 is available as a direct update. To upgrade, run a command to set the upgrade tier and follow the required actions to complete the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.cpanel.net/hc/en-us/articles/40311033698327-Security-CVE-2026-29201-cPanel-WHM-WP2-Security-Update-May-08-2026 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cPanel | All versions |
CPE
Remediation
| |
| cPanel WHM | All versions |
CPE
Remediation
| |
| cPanel WP Squared | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | CVE Modified | [email protected] |
| May 8, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion