CVE-2026-29205

HIGH

cPanel 11.120.0.0-11.136.0.9 Arbitrary File Read via cpdavd

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2026-29205. PoCs published by Unclecheng-li, MillerDetach, SmashMythAmp.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-29205, a CalDAV path-traversal vulnerability in cPanel/WHM, allowing arbitrary file reads as root. It includes a scanner for CVE-2026-41940 (authentication bypass) and an exploit chain for CVE-2026-29205, leveraging SMTP sub-addressing to create malicious maildir folders and exfiltrate files via CalDAV.

Description

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Exploits (4)

github WORKING POC 359 stars
by Unclecheng-li · cpoc
https://github.com/Unclecheng-li/poc-lab/tree/main/CVE-2026-29205 cPanel2Shell-Scanner

This repository contains a functional exploit for CVE-2026-29205, a CalDAV path-traversal vulnerability in cPanel/WHM, allowing arbitrary file reads as root. It includes a scanner for CVE-2026-41940 (authentication bypass) and an exploit chain for CVE-2026-29205, leveraging SMTP sub-addressing to create malicious maildir folders and exfiltrate files via CalDAV.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Complex
Reliability
Reliable
Target: cPanel/WHM (versions prior to 11.134.0.26)
No auth needed
Prerequisites: SMTP relay access for sending emails · target host running vulnerable cPanel/WHM · CalDAV service (cpdavd) accessible on ports 2079/2080
mistral-large-3 · analyzed May 25, 2026 Full analysis →
github WORKING POC
by MillerDetach · pythonpoc
https://github.com/MillerDetach/poc-lab-pro/tree/main/CVE-2026-29205 cPanel2Shell-Scanner

This repository contains a functional exploit scanner for CVE-2026-29205, a pre-authentication arbitrary file read vulnerability in cPanel/WHM's CalDAV daemon (cpdavd). The exploit leverages SMTP plus addressing to create a malicious maildir folder and then uses CalDAV path traversal to read files as root.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Complex
Reliability
Reliable
Target: cPanel/WHM (cpdavd) versions before 11.134.0.26
No auth needed
Prerequisites: cpdavd accessible (ports 2079/2080) · valid cPanel virtual mailbox · ability to deliver emails to the target mailbox
mistral-large-3 · analyzed Jun 09, 2026 Full analysis →
github WORKING POC
by SmashMythAmp · pythonpoc
https://github.com/SmashMythAmp/poc-lab-605/tree/main/CVE-2026-29205 cPanel2Shell-Scanner

This repository contains a functional exploit scanner for CVE-2026-29205, a pre-authentication arbitrary file read vulnerability in cPanel/WHM's CalDAV daemon (cpdavd). The exploit leverages SMTP plus addressing to create a malicious maildir folder and then uses CalDAV path traversal to read files as root.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Complex
Reliability
Reliable
Target: cPanel/WHM (cpdavd) versions before 11.134.0.26
No auth needed
Prerequisites: Access to cpdavd (ports 2079/2080) · Valid cPanel virtual mailbox · Ability to deliver emails to the target mailbox · CalDAV attachment read path accessibility
mistral-large-3 · analyzed Jun 06, 2026 Full analysis →
github WORKING POC
by LadyAqueduct · htmlpoc
https://github.com/LadyAqueduct/poc-lab-798/tree/main/CVE-2026-29205 cPanel2Shell-Scanner

This repository contains a functional exploit for CVE-2026-29205, a pre-authentication path traversal vulnerability in cPanel/WHM's CalDAV daemon (cpdavd). The exploit leverages SMTP plus alias to create a directory structure that enables arbitrary file reads as root due to a permission downgrade object lifecycle error.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Complex
Reliability
Reliable
Target: cPanel/WHM (versions prior to 11.134.0.26)
No auth needed
Prerequisites: Access to cpdavd (ports 2079/2080) · Valid cPanel virtual email account · Ability to deliver emails to the target
mistral-large-3 · analyzed Jun 06, 2026 Full analysis →

Scores

CVSS v3 8.6
EPSS 0.0724
EPSS Percentile 93.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-250
Status published
Products (7)
WebPros/cPanel 11.120.0.0 - 11.124.0.38
WebPros/cPanel 11.126.0.0 - 11.126.0.59
WebPros/cPanel 11.130.0.0 - 11.130.0.23
WebPros/cPanel 11.132.0.0 - 11.132.0.32
WebPros/cPanel 11.134.0.0 - 11.134.0.26
WebPros/cPanel 11.136.0.0 - 11.136.0.10
WebPros/WP Squared 11.120.1.0 - 11.136.1.12
Published May 13, 2026
Tracked Since May 14, 2026