Security: CVE-2026-29206 – cPanel & WHM / WP2 Security Update – May 13, 2026
It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. This affects all cPanel & WHM versions.
CMD de actualización por defecto
sudo /scripts/upcp --force
Lo que esto significa bajo una licencia de SharedLicense
Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.
Situation
It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. This affects all cPanel & WHM versions.
Impact
We have pushed out a patch in the following cPanel & WHM versions:
- 11.86.0.44 and higher
- 11.94.0.31 and higher
- 11.102.0.42 and higher
- 11.110.0.118 (cl6110)
- 11.110.0.119 and higher
- 11.118.0.67 and higher
- 11.124.0.38 and higher
- 11.126.0.59 and higher
- 11.130.0.23 and higher
- 11.132.0.32 and higher
- 11.134.0.26 and higher
- 11.136.0.10 and higher
We have pushed out a patch in the following WP Squared version:
- 11.136.1.12 and higher
For customers still on CentOS 6 or CloudLinux 6, we recommend running the following command to set the upgrade tier, and then following the steps in the “Required Actions” below.
# sed -i “s/CPANEL=.*/CPANEL=cl6110/g” /etc/cpupdate.conf
Note: All further versions of cPanel are patched for this issue as well. Please see the latest changelogs for version information of each cPanel branch:
https://docs.cpanel.net/changelogs/
Call to Action
-
Update the cPanel version on the server to one of the versions listed above. This can be done with the following:
# /scripts/upcp –force
-
Once completed, verify the cPanel version with the following to ensure the update was successful.
# /usr/local/cpanel/cpanel -V
Additional Information
Additional security incidents are resolved in this latest release as well. Please see the following for more information:
Preguntas frecuentes
What is CVE-2026-29206?
Is CVE-2026-29206 being exploited in the wild?
How do I fix CVE-2026-29206?
Why does this advisory list several CVEs?
Referencias
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema