Home

Description

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

PUBLISHED Reserved 2026-03-04 | Published 2026-05-13 | Updated 2026-05-14 | Assigner hackerone




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Problem types

CWE-89 SQL Injection

Product status

Default status
unaffected

11.136.0.0 (semver) before 11.136.0.10
affected

11.134.0.0 (semver) before 11.134.0.26
affected

11.132.0.0 (semver) before 11.132.0.32
affected

11.130.0.0 (semver) before 11.130.0.23
affected

11.126.0.0 (semver) before 11.126.0.59
affected

11.124.0.0 (semver) before 11.124.0.38
affected

11.118.0.0 (semver) before 11.118.0.67
affected

11.110.0.0 (semver) before 11.110.0.119
affected

11.102.0.0 (semver) before 11.102.0.42
affected

11.94.0.0 (semver) before 11.94.0.31
affected

11.30.0.0 (semver) before 11.86.0.44
affected

Default status
unaffected

11.136.1.0 (semver) before 11.136.1.12
affected

Default status
unaffected

11.110.0.0 (semver) before 11.110.0.118
affected

References

support.cpanel.net/...el-WHM-WP2-Security-Update-May-13-2026

cve.org (CVE-2026-29206)

nvd.nist.gov (CVE-2026-29206)

Download JSON