Back to search
CVE-2026-29203
Published: May 8, 2026
Modified: May 15, 2026
PUBLISHED
Description
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home directory.
| Vendor | Product | Versions |
|---|---|---|
WebPros | cPanel | affected 11.136.0.0 - < 11.136.0.9affected 11.134.0.0 - < 11.134.0.25affected 11.132.0.0 - < 11.132.0.31affected 11.130.0.0 - < 11.130.0.22affected 11.126.0.0 - < 11.126.0.58+6 more versions |
WebPros | cPanel (CloudLinux 6, CentOS 6) | affected 11.110.0.0 - < 11.110.0.116 |
WebPros | WP Squared | affected 11.136.1.0 - < 11.136.1.10 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now