このページはまだあなたの言語に翻訳されていません。翻訳作業中のため、英語でコンテンツを表示しています。

💡 Keep dependencies up to date — most exploits target known, patchable vulnerabilities.

HIGHCVE-2026-32993CVSS 8.3

CVE-2026-32993: HTTP Header Injection in cPanel

プラットフォーム

cpanel

コンポーネント

cpanel

修正版

11.136.1.12

あなたの言語に翻訳中…

CVE-2026-32993 is a high-severity vulnerability affecting cPanel versions 11.132.0.0 through 11.136.1.12. This vulnerability stems from improper input sanitization within the /unprotected/nova_error endpoint, allowing an unauthenticated attacker to inject arbitrary HTTP headers into the server's response. Successful exploitation could lead to redirection attacks or other malicious actions, compromising the integrity of the web server and potentially impacting hosted websites.

影響と攻撃シナリオ翻訳中…

The impact of CVE-2026-32993 is significant due to its unauthenticated nature and the potential for HTTP header injection. An attacker could leverage this vulnerability to redirect users to malicious websites (phishing), inject tracking headers for data exfiltration, or even modify the server's behavior by manipulating response headers. This could lead to credential theft, malware distribution, or defacement of hosted websites. The lack of authentication lowers the barrier to entry, making it accessible to a wider range of attackers. The /unprotected/nova_error endpoint is often overlooked in security assessments, making this a particularly concerning vulnerability.

悪用の状況翻訳中…

CVE-2026-32993 was published on May 13, 2026. Its severity is rated HIGH (CVSS 8.3). Currently, there are no publicly known active campaigns exploiting this vulnerability. No KEV or EPSS score is available at this time. Monitor security advisories and threat intelligence feeds for any indications of exploitation.

脅威インテリジェンス

エクスプロイト状況

概念実証不明
CISA KEVNO
インターネット露出
レポート1 脅威レポート

CISA SSVC

悪用状況none
自動化可能yes
技術的影響partial

CVSS ベクトル

脅威インテリジェンス· CVSS 3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L8.3HIGHAttack VectorNetwork攻撃者がターゲットに到達する方法Attack ComplexityLow悪用に必要な条件Privileges RequiredNone攻撃に必要な認証レベルUser InteractionNone被害者の操作が必要かどうかScopeChanged影響コンポーネント外への波及ConfidentialityLow機密データ漏洩のリスクIntegrityLow不正データ改ざんのリスクAvailabilityLowサービス障害のリスクnextguardhq.com · CVSS v3.1 基本スコア
これらのメトリクスの意味は?
Attack Vector
ネットワーク — インターネット経由でリモートから悪用可能。物理・ローカルアクセス不要。
Attack Complexity
低 — 特別な条件不要。安定して悪用可能。
Privileges Required
なし — 認証不要。資格情報なしで悪用可能。
User Interaction
なし — 自動かつ無音の攻撃。被害者は何もしない。
Scope
変化あり — 攻撃が脆弱なコンポーネントを超えて他のシステムに波及可能。
Confidentiality
低 — 一部データへの部分的アクセス。
Integrity
低 — 限定的な範囲でデータ変更可能。
Availability
低 — 部分的または断続的なサービス拒否。

影響を受けるソフトウェア

コンポーネントcpanel
ベンダーWebPros
最小バージョン11.132.0.0
最大バージョン11.136.1.12
修正版11.136.1.12

弱点分類 (CWE)

タイムライン

  1. 予約済み
  2. 公開日
  3. 更新日

緩和策と回避策翻訳中…

The primary mitigation for CVE-2026-32993 is to upgrade cPanel to version 11.136.1.12 or later, which contains the necessary fix. If immediate upgrade is not possible, consider implementing a Web Application Firewall (WAF) rule to block requests containing suspicious characters or patterns in the status query parameter of the /unprotected/novaerror endpoint. Alternatively, restrict access to the /unprotected/novaerror endpoint to trusted networks or IP addresses. Thoroughly review and harden cPanel's configuration, ensuring that all unnecessary features and endpoints are disabled. After upgrading, confirm the fix by attempting to inject a custom HTTP header via the /unprotected/nova_error endpoint; the request should be rejected.

修正方法翻訳中…

Actualice cPanel a la versión 11.132.0.32 o posterior, 11.134.0.26 o posterior, 11.136.0.10 o posterior, o 11.136.1.12 o posterior para mitigar la vulnerabilidad.  La actualización corrige la falta de sanitización adecuada del parámetro de consulta 'status' en el endpoint '/unprotected/nova_error', previniendo la inyección de encabezados HTTP arbitrarios.

よくある質問翻訳中…

What is CVE-2026-32993 — HTTP Header Injection in cPanel?

CVE-2026-32993 is a high-severity vulnerability in cPanel versions 11.132.0.0–11.136.1.12 that allows unauthenticated attackers to inject arbitrary HTTP headers via the /unprotected/nova_error endpoint, potentially leading to redirection or data exfiltration.

Am I affected by CVE-2026-32993 in cPanel?

You are affected if you are running cPanel versions 11.132.0.0 through 11.136.1.12. Check your cPanel version using /usr/local/cpanel/cpversion.

How do I fix CVE-2026-32993 in cPanel?

Upgrade cPanel to version 11.136.1.12 or later. As a temporary workaround, implement a WAF rule to block suspicious requests to the /unprotected/nova_error endpoint.

Is CVE-2026-32993 being actively exploited?

Currently, there are no publicly known active campaigns exploiting CVE-2026-32993, but it's crucial to apply the patch promptly.

Where can I find the official cPanel advisory for CVE-2026-32993?

Refer to the official cPanel security advisory for CVE-2026-32993 on the cPanel website (https://security.cpanel.net/ - search for CVE-2026-32993).

あなたのプロジェクトは影響を受けていますか?

依存関係ファイルをアップロードすれば、このCVEや他のCVEがあなたに影響するか即座にわかります。

scanZone.liveBadgescanZone.eyebrow

今すぐ試す — アカウント不要

Upload any manifest (composer.lock, package-lock.json, WordPress plugin list…) or paste your component list. You get a vulnerability report instantly. Uploading a file is just the start: with an account you get continuous monitoring, Slack/email alerts, multi-project and white-label reports.

手動スキャンSlack/メールアラートContinuous monitoringホワイトラベルレポート

依存関係ファイルをドラッグ&ドロップ

composer.lock、package-lock.json、requirements.txt、Gemfile.lock、pubspec.lock、Dockerfile...