Sploitus

CVE-2026-29205

No indexed exploits for CVE-2026-29205 yet

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Cpanel
< 124.0.38, 126.0.59, 130.0.23, 132.0.32, 134.0.26, 136.0.10
Cpanel Wp Squared
< 136.1.12
CVSS 3.1
8.6 HIGH
EPSS
8.2% (94th percentile)
Weakness
CWE-250
NVD status
Analyzed
Published
2026-05-13
CVE-2026-29205 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-29205 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-29205 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.