Skip to content
CVE-2026-29201

CVE-2026-29201

support.cpanel.net May 10, 2026

An arbitrary file read found was found in the feature::LOADFEATUREFILE adminbin call where it does not adequately validate the feature file name. A relative path may be passed as the argument to this call, causing an arbitrary file to be made world-readable.

We have pushed out a patch in the following cPanel & WHM versions:

We have pushed out a patch in the following WP Squared version:

For customers still on CentOS 6 or CloudLinux 6, we have also released v110.0.114 as a direct update. To upgrade to this version, run the following command to set the upgrade tier, and then follow the steps in the "Required Actions" below.

# sed -i "s/CPANEL=.*/CPANEL=cl6110/g" /etc/cpupdate.conf

Note: All further versions of cPanel are patched for this issue as well. Please see the latest changelogs for version information of each cPanel branch:

Update the cPanel version on the server to one of the versions listed above. This can be done with the following:

# /scripts/upcp --force

Once completed, verify the cPanel version with the following to ensure the update was successful.

# /usr/local/cpanel/cpanel -V

Additional security incidents are resolved in this latest release as well. Please see the following for more information:

Security: CVE-2026-29202 - cPanel & WHM / WP2 Security Update - May 08, 2026

Security: CVE-2026-29203 - cPanel & WHM / WP2 Security Update - May 08, 2026