SQL Injection Vulnerability in cPanel WHM's sqloptimizer Utility
CVE-2026-29206

8.1HIGH

Key Information:

Vendor

Webpros

Vendor
CVE Published:
13 May 2026

What is CVE-2026-29206?

The sqloptimizer utility script in cPanel WHM has a vulnerability due to insufficient sanitization of SQL queries. This flaw enables potential SQL injection attacks, allowing unauthorized manipulation of the database when Slow Query logging is activated. It is crucial for users to update their cPanel WHM installations to mitigate these risks and protect their web hosting environments effectively.

Affected Version(s)

cPanel 11.136.0.0 < 11.136.0.10

cPanel 11.134.0.0 < 11.134.0.26

cPanel 11.132.0.0 < 11.132.0.32

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.