Web Hack List

Preliminary research

cPanel file read through SMTP-created paths and CalDAV parser collisions

New Age of Collisions: Reading Arbitrary Files Pre-Auth as Root in cPanel (CVE-2026-29205)

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Uses SMTP plus-address delivery to create a Maildir path required by a CalDAV attachment route. Later decoding and traversal expose another file, while an unretained privilege-reduction object restores elevated access too early; the chain combines cross-protocol filesystem preparation with path and object-lifetime mistakes.

Record

Document
New Age of Collisions: Reading Arbitrary Files Pre-Auth as Root in cPanel (CVE-2026-29205)
Researcher
Shubham Shah and Adam Kues
Published by
Searchlight Cyber
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Shubham Shah and Adam Kues, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .