Вернуться к предупреждениям о безопасности

Security: CVE-2026-32991 – cPanel & WHM / WP2 Security Update – May 13, 2026

It was found that a low-privilege team user (role=default) can escalate to the owner account's full capabilities through the use of certain UAPI modules. This affects cPanel & WHM versions 110 and higher.

High 7.1 CVSS
CloudLinux cPanel

Команда обновления по умолчанию

sudo /scripts/upcp --force

Что это значит по лицензии SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

It was found that a low-privilege team user (role=default) can escalate to the owner account’s full capabilities through the use of certain UAPI modules. This affects cPanel & WHM versions 110 and higher.

Impact

We have pushed out a patch in the following cPanel & WHM versions: 

  • 11.110.0.118 (cl6110)
  • 11.110.0.119 and higher
  • 11.118.0.67 and higher
  • 11.124.0.38 and higher
  • 11.126.0.59 and higher
  • 11.130.0.23 and higher
  • 11.132.0.32 and higher
  • 11.134.0.26 and higher
  • 11.136.0.10 and higher

We have pushed out a patch in the following WP Squared version:

  • 11.136.1.12 and higher

For customers still on CentOS 6 or CloudLinux 6, we recommend running the following command to set the upgrade tier, and then following the steps in the “Required Actions” below.

# sed -i “s/CPANEL=.*/CPANEL=cl6110/g” /etc/cpupdate.conf

Note: All further versions of cPanel are patched for this issue as well. Please see the latest changelogs for version information of each cPanel branch:
https://docs.cpanel.net/changelogs/

Call to Action

  1. Update the cPanel version on the server to one of the versions listed above. This can be done with the following:

    # /scripts/upcp –force

  2. Once completed, verify the cPanel version with the following to ensure the update was successful.

    # /usr/local/cpanel/cpanel -V

Additional Information

Additional security incidents are resolved in this latest release as well. Please see the following for more information:

Часто задаваемые вопросы

What is CVE-2026-32991?
Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.
Is CVE-2026-32991 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.23% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-32991?
Update CloudLinux, cPanel to the patched release.Then confirm the running version matches the patched release listed above.
Why does this advisory list several CVEs?
One vendor release fixed multiple vulnerabilities. This advisory covers CVE-2026-32991, CVE-2026-29205, CVE-2026-29206, CVE-2026-32992, CVE-2026-32993 — updating to the patched release resolves all of them at once.

Проверьте систему на уязвимости

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Проверьте свою систему