PT-2026-97063 · Cpanel · Cpanel
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
cPanel/WHM versions 120 through 11.133.x
cPanel/WHM versions 11.134.0 through 11.134.0.56
cPanel/WHM versions 11.136.0 through 11.136.0.40
cPanel/WHM versions 11.138.0 through 11.138.0.7
WP2 versions prior to 11.138.1.11
Description
Remote authenticated users can escalate privileges through the CalDAV and CardDAV functionality. This issue allows an authenticated account holder to execute arbitrary code with root privileges, which can lead to full server compromise.
Recommendations
Update cPanel/WHM to version 11.134.0.57 or newer for the 11.134 branch.
Update cPanel/WHM to version 11.136.0.41 or newer for the 11.136 branch.
Update cPanel/WHM to version 11.138.0.8 or newer for the 11.138 branch.
Update WP2 to version 11.138.1.11 or newer.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpanel