Does cPanel provide fixes for CVE-2026-66140 and GCVE-25-2026-07-45-3?
cPanel’s version of Exim does provide fixes for GCVE-25-2026-07-45-1 (CVE-2026-66140) and GCVE-25-2026-07-45-3. cPanel patched this as part of cpanel-exim-4.99.5-1. The cPanel Exim 4.99.5-1 release was included as of the following versions:
- 11.110.0.137
- 11.118.0.71
- 11.126.0.78
- 11.134.0.48
- 11.136.0.32
- 11.138 and later
If you are running an older version, you can update cPanel through WHM or by running the following command:
/scripts/upcpGCVE-25-2026-07-45-3
Section titled “GCVE-25-2026-07-45-3”Under cPanel’s Exim default configuration, this expansion and execution occurs as the cPanel user. This may allow for privilege escalation from Team User sub-accounts.
Mitigation
Section titled “Mitigation”Servers that cannot immediately upgrade should review their mail delivery configuration for any options that force command execution (force_command) on locally-forwarded mail, and remove or disable them as a temporary workaround until the upgrade can be applied. Once the patch is applied, it would be safe to re-enable or reapply force_command.
GCVE-25-2026-07-45-1 (CVE-2026-66140)
Section titled “GCVE-25-2026-07-45-1 (CVE-2026-66140)”Using command-line arguments intended for transferring queue-name through an Exim execution chain, files outside the spool area can be accessed. This can be used for a privilege escalation.
Mitigation
Section titled “Mitigation”There is no known mitigation for this issue other than upgrading to a patched version of cPanel.