EIP-2026-106208

PRE-CVE

cPanel 10.8.x - 'cpwrap' via MySQLAdmin Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106208. PoCs published by Nima Salehi.

AI-analyzed exploit summary This PHP exploit targets a vulnerability in cPanel <= 10.8.x by leveraging the 'mysqlwrap' binary to execute arbitrary commands via a crafted Perl module. It requires the ability to upload a PHP file to the target server and bypasses safe_mode and disabled functions checks.

Description

cPanel 10.8.x - 'cpwrap' via MySQLAdmin Privilege Escalation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nima Salehi · phpwebappsphp
https://www.exploit-db.com/exploits/2554

This PHP exploit targets a vulnerability in cPanel <= 10.8.x by leveraging the 'mysqlwrap' binary to execute arbitrary commands via a crafted Perl module. It requires the ability to upload a PHP file to the target server and bypasses safe_mode and disabled functions checks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: cPanel <= 10.8.x
No auth needed
Prerequisites: Ability to upload a PHP file to the target server · Perl installed on the target system · cPanel <= 10.8.x installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026