Home

Description

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.

PUBLISHED Reserved 2026-03-04 | Published 2026-05-08 | Updated 2026-05-13 | Assigner hackerone




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-94 Code Injection

Product status

Default status
unaffected

11.136.0.0 (semver) before 11.136.0.9
affected

11.134.0.0 (semver) before 11.134.0.25
affected

11.132.0.0 (semver) before 11.132.0.31
affected

11.130.0.0 (semver) before 11.130.0.22
affected

11.126.0.0 (semver) before 11.126.0.58
affected

11.124.0.0 (semver) before 11.124.0.37
affected

11.118.0.0 (semver) before 11.118.0.66
affected

11.110.0.0 (semver) before 11.110.0.117
affected

11.102.0.0 (semver) before 11.102.0.41
affected

11.94.0.0 (semver) before 11.94.0.30
affected

11.86.0.0 (semver) before 11.86.0.43
affected

Default status
unaffected

11.110.0.0 (semver) before 11.110.0.116
affected

Default status
unaffected

11.136.1.0 (semver) before 11.136.1.11
affected

References

support.cpanel.net/...el-WHM-WP2-Security-Update-May-08-2026

cve.org (CVE-2026-29202)

nvd.nist.gov (CVE-2026-29202)

Download JSON