Back to Security Advisories

Security: CVE-2026-29206 – cPanel & WHM / WP2 Security Update – May 13, 2026

It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. This affects all cPanel & WHM versions.

High
CloudLinux cPanel

Default Update CMD

sudo /scripts/upcp --force

Situation

It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. This affects all cPanel & WHM versions.

Impact

We have pushed out a patch in the following cPanel & WHM versions: 

  • 11.86.0.44 and higher
  • 11.94.0.31 and higher
  • 11.102.0.42 and higher
  • 11.110.0.118 (cl6110)
  • 11.110.0.119 and higher
  • 11.118.0.67 and higher
  • 11.124.0.38 and higher
  • 11.126.0.59 and higher
  • 11.130.0.23 and higher
  • 11.132.0.32 and higher
  • 11.134.0.26 and higher
  • 11.136.0.10 and higher

We have pushed out a patch in the following WP Squared version:

  • 11.136.1.12 and higher

For customers still on CentOS 6 or CloudLinux 6, we recommend running the following command to set the upgrade tier, and then following the steps in the “Required Actions” below.

# sed -i “s/CPANEL=.*/CPANEL=cl6110/g” /etc/cpupdate.conf

Note: All further versions of cPanel are patched for this issue as well. Please see the latest changelogs for version information of each cPanel branch:
https://docs.cpanel.net/changelogs/

Call to Action

  1. Update the cPanel version on the server to one of the versions listed above. This can be done with the following:

    # /scripts/upcp –force

  2. Once completed, verify the cPanel version with the following to ensure the update was successful.

    # /usr/local/cpanel/cpanel -V

Additional Information

Additional security incidents are resolved in this latest release as well. Please see the following for more information:

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Check Your System