Description
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Published: 2026-05-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Disclosure via Web Endpoint
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from improper privilege handling and insufficient path filtering in the cpdavd attachment download endpoints, enabling an attacker to read any file on the server. This flaw can expose configuration files, credentials, and other sensitive data, compromising confidentiality and potentially enabling further exploitation.

Affected Systems

The flaw affects WebPros’ WP Squared and cPanel products. No specific version numbers are listed in the advisory, so any installation of these products may be impacted until the issue is patched.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of <1% denotes a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed wild exploits yet. The likely attack vector is a web‑based request to a cpdavd endpoint, potentially requiring user authentication but not guaranteed to be unauthenticated, allowing an attacker to read arbitrary files if the endpoints are reachable.

Generated by OpenCVE AI on September 24, 2026 at 20:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest cPanel security update that addresses CVE‑2026‑29205 via the official support channel.
  • Restrict access to the cpdavd endpoints by enforcing IP whitelisting or strict authentication to limit exposure.
  • Reconfigure the service so it serves files only from validated upload directories and blocks path traversal attempts.

Generated by OpenCVE AI on September 24, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Arbitrary File Read via cpdavd Attachment Download Endpoint

Wed, 12 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Cpanel
Cpanel cpanel
Cpanel whm
Cpanel wp Squared
CPEs cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*
Vendors & Products Cpanel
Cpanel cpanel
Cpanel whm
Cpanel wp Squared

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Arbitrary File Read via cpdavd Attachment Download Endpoint

Wed, 17 Jun 2026 11:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Read via cpdavd Attachment Download Endpoint

Tue, 16 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
Title File Disclosure via cpdavd Attachment Download Endpoint

Thu, 14 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 May 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros cpanel
Webpros wp Squared
Wordpress
Wordpress wordpress
Vendors & Products Webpros
Webpros cpanel
Webpros wp Squared
Wordpress
Wordpress wordpress

Wed, 13 May 2026 23:45:00 +0000

Type Values Removed Values Added
Title File Disclosure via cpdavd Attachment Download Endpoint

Wed, 13 May 2026 22:15:00 +0000

Type Values Removed Values Added
Description Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Cpanel Cpanel Whm Wp Squared
Webpros Cpanel Wp Squared
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-05-14T13:13:52.380Z

Reserved: 2026-03-04T15:00:09.267Z

Link: CVE-2026-29205

cve-icon Vulnrichment

Updated: 2026-05-14T13:13:43.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-13T22:16:42.817

Modified: 2026-08-12T18:34:24.737

Link: CVE-2026-29205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T21:00:18Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges