CVE-2026-29205
HIGH
8,6
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: low
Availability: low
Description
AI Translation Available
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
250
Execution with Unnecessary Privileges
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Read Application Data
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
AI/ML, Mobile
https://support.cpanel.net/hc/en-us/articles/40437020299927-Security-CVE-2026-2…