PT-2026-40436 · Cpdavd · Cpdavd

Published

2026-05-12

·

Updated

2026-05-14

·

CVE-2026-29205

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions cPanel versions prior to 11.134.0.26
Description Incorrect privileges management and insufficient path filtering allow an attacker to read arbitrary files on the server via the 'cpdavd attachment download' endpoints.
Recommendations Update to a version later than 11.134.0.26.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-29205

Affected Products

Cpdavd