High · published September 1, 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
| Product | Versions | Fixed in |
|---|---|---|
| cpanel/cpanel | < 11.110.0.141 | 11.110.0.141 |
| cpanel/cpanel | ≥ 11.112.0.0, < 11.134.0.53 | 11.134.0.53 |
| cpanel/cpanel | ≥ 11.136.0.0, < 11.136.0.37 | 11.136.0.37 |
| cpanel/cpanel | ≥ 11.138.0.0, < 11.138.0.2 | 11.138.0.2 |
| cpanel/cpanel | ≥ 11.138.1.0, < 11.138.1.7 | 11.138.1.7 |