[WID-SEC-2026-3277] cPanel cPanel/WHM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten CVSS Base Score 9.9 (kritisch) CVSS Temporal Score 8.6 (hoch) Remoteangriff ja Datum 08.09.2026 Stand 09.09.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung cPanel ist eine Software für die Verwaltung von Webhosting Auftritten. Die Software ermöglicht es dem Endanwender, Statistiken einzusehen, neue Benutzeraccounts anzulegen, Maileinstellungen zu verändern und vieles mehr. Produkte 08.09.2026 cPanel cPanel/WHM <v11.110.0.143 cPanel cPanel/WHM <v11.134.0.55 cPanel cPanel/WHM <v11.136.0.39 cPanel cPanel/WHM <v11.138.0.4 cPanel cPanel/WHM WP2 <v11.138.1.9 Angriff Angriff Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in cPanel cPanel/WHM ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical vulnerability (CVSS Base Score 9.9) in cPanel/WHM allows a remote, authenticated attacker to execute arbitrary code with administrator privileges. Affected versions are cPanel/WHM prior to v11.110.0.143, v11.134.0.55, v11.136.0.39, v11.138.0.4, and cPanel/WHM WP2 prior to v11.138.1.9. A mitigation is available, though the article does not specify a single fixed version or provide workaround details.