← Back to Vulnerability Reports CVE Intelligence

CVE-2026-29201

cPanel & WHMHIGH · CVSS 8.6No exploitation reported

What is CVE-2026-29201?

Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.

CVSS8.6 NVD 3.1
SeverityHIGH
ExploitationNo exploitation reported
Triage statusNo Known Exploit
ActionPatch this week
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
NVD published2026-05-08
NVD last modified2026-05-13

Affected product

cPanel & WHM

Remediation Steps

  1. Download latest cPanel/WHM security updates from vendor
  2. Test patches on non-production hosting environments
  3. Deploy patches during maintenance window with communication to users
  4. Verify file permissions and feature loading mechanisms post-update
  5. Monitor error logs for any compatibility issues with custom configurations
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.