
@ITSecurityguard 11.124.0.40 and higher 11.126.0.61 and higher 11.130.0.25 and higher 11.132.0.34 and higher 11.134.0.28 and higher 11.136.0.12 and higher these are affected or patched versions
English
Gee Jam
1 posts



Our security research team discovered a pre-authentication arbitrary file read as root in cPanel (CVE-2026-29205) — a path traversal in cpdavd that we made exploitable by abusing Dovecot's + alias handling to create attacker-controlled directory names on disk. We've updated cpanel2shell-scanner to cover both issues. Writeup and tool in replies. 👇