Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-26107
cPanel vulnerability analysis and mitigation

Overview

CVE-2020-26107 affects cPanel versions before 88.0.3, where upon an upgrade, the system establishes predictable PowerDNS API keys (identified as SEC-561). The vulnerability was disclosed on September 25, 2020, and impacts cPanel installations that utilize PowerDNS functionality (NVD Database).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability is classified under CWE-330 (Use of Insufficiently Random Values), indicating issues with the generation of API keys that could be predicted by attackers (NVD Database).

Impact

The vulnerability exposes systems to potential unauthorized access through predictable PowerDNS API keys. With the CVSS score indicating high confidentiality impact but no impact on integrity or availability, the primary risk is unauthorized access to DNS management functions (NVD Database).

Exploitability

The vulnerability has a network attack vector (AV:N) with low attack complexity (AC:L) and requires no privileges (PR:N) or user interaction (UI:N), making it relatively straightforward to exploit if unpatched (NVD Database).

Mitigation and workarounds

The vulnerability has been fixed in cPanel version 88.0.3 and later releases. Users should upgrade their cPanel installations to version 88.0.3 or newer to address this security issue (NVD Database).

Additional resources


SourceThis report was generated using AI

Related cPanel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58048CRITICAL9.4
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesJul 31, 2026
CVE-2026-41940CRITICAL9.3
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
YesYesApr 29, 2026
CVE-2026-65643HIGH8.7
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesSep 01, 2026
CVE-2026-29205HIGH8.6
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesMay 13, 2026
CVE-2026-32992HIGH8.2
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management