Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 15 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Traversal Allowing Local Privilege Escalation in cPanel Nova |
Fri, 15 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webpros
Webpros cpanel Webpros cpanel (centos 6, Cloudlinux 6) Webpros wp Squared |
|
| Vendors & Products |
Webpros
Webpros cpanel Webpros cpanel (centos 6, Cloudlinux 6) Webpros wp Squared |
Fri, 08 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Symlink Traversal Allowing Local Privilege Escalation in cPanel Nova |
Fri, 08 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home directory. | |
| Weaknesses | CWE-61 | |
| References |
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-05-15T17:14:52.318Z
Reserved: 2026-03-04T15:00:09.267Z
Link: CVE-2026-29203
Updated: 2026-05-08T19:20:00.014Z
Status : Awaiting Analysis
Published: 2026-05-08T19:16:30.147
Modified: 2026-05-15T18:16:14.443
Link: CVE-2026-29203
No data.
OpenCVE Enrichment
Updated: 2026-05-15T20:30:06Z