EIP-2026-106208
PRE-CVEcPanel 10.8.x - 'cpwrap' via MySQLAdmin Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-106208. PoCs published by Nima Salehi.
AI-analyzed exploit summary This PHP exploit targets a vulnerability in cPanel <= 10.8.x by leveraging the 'mysqlwrap' binary to execute arbitrary commands via a crafted Perl module. It requires the ability to upload a PHP file to the target server and bypasses safe_mode and disabled functions checks.
Description
cPanel 10.8.x - 'cpwrap' via MySQLAdmin Privilege Escalation
Exploits (1)
This PHP exploit targets a vulnerability in cPanel <= 10.8.x by leveraging the 'mysqlwrap' binary to execute arbitrary commands via a crafted Perl module. It requires the ability to upload a PHP file to the target server and bypasses safe_mode and disabled functions checks.