cPanel Releases Security Update for Three Vulnerabilities Including CVE-2026-29201
Patch cPanel to the latest security release to fix the feature::LOADFEATUREFILE input validation flaw (CVE-2026-29201).
Patch cPanel to the latest security release (≥ current version) to address CVE-2026-29201 and related vulnerabilities.
Summary
cPanel has released a security update addressing three vulnerabilities that could lead to privilege escalation, code execution, and denial‑of‑service.
The most detailed flaw is CVE-2026-29201, CVSS 4.3, caused by insufficient input validation of the feature file name in the "feature::LOADFEATUREFILE" adminbin call. This flaw could allow an attacker to upload arbitrary files and gain elevated privileges.
The update also covers two other undisclosed vulnerabilities that could impact cPanel and Web Host Manager (WHM) installations. Administrators should apply the latest patch immediately to mitigate the risk.
Key changes
- CVE-2026-29201, CVSS 4.3, insufficient input validation in feature::LOADFEATUREFILE adminbin call
- Vulnerability could lead to privilege escalation, code execution, and denial‑of‑service
- Affects cPanel and Web Host Manager (WHM) installations
- cPanel has released a security update addressing the flaw
- The update also covers two other undisclosed vulnerabilities