Vulnerability intelligence
CVE-2026-29202
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
CVSS Score
8.8
High
EPSS — Exploit Probability
1.9%
Riskier than 78% of all CVEs · checked 2026-09-08
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
2 articles across 2 outlets · first covered May 9, 2026 · latest May 10, 2026
Coverage timeline
-
New cPanel vulnerabilities could allow file access and remote code executionsecurityaffairs.com · May 10, 2026
-
cPanel fixes bugs enabling code execution or privilege escalationthehackernews.com · May 9, 2026