This security advisory applies only to users who manage their own VPS or Dedicated Server with a cPanel license.
Shared Hosting and normal cPanel Hosting users do not need to take any action.
cPanel has reported a security issue related to symlink access through File Manager. In certain cases, a cPanel user may be able to access symlinks through File Manager that would normally not be accessible through SSH.
Depending on file permissions, this could potentially expose information that the user would not normally have access to.
Patched cPanel Versions:
- v11.110.0.134 and greater
- v11.126.0.77 and greater
- v11.134.0.44 and greater
- v11.136.0.28 and greater
Server administrators should update cPanel to the latest patched version using the following command:
/scripts/upcp --force
Official cPanel Advisory:
Once again, Shared Hosting, Reseller Hosting, and regular cPanel Hosting customers do not need to run this command or take any action.
Giovedì, Luglio 9, 2026