Skip to content

Does cPanel provide fixes for CVE-2026-66140 and GCVE-25-2026-07-45-3?

cPanel’s version of Exim does provide fixes for GCVE-25-2026-07-45-1 (CVE-2026-66140) and GCVE-25-2026-07-45-3. cPanel patched this as part of cpanel-exim-4.99.5-1. The cPanel Exim 4.99.5-1 release was included as of the following versions:

  • 11.110.0.137
  • 11.118.0.71
  • 11.126.0.78
  • 11.134.0.48
  • 11.136.0.32
  • 11.138 and later

If you are running an older version, you can update cPanel through WHM or by running the following command:

Terminal window
/scripts/upcp

Under cPanel’s Exim default configuration, this expansion and execution occurs as the cPanel user. This may allow for privilege escalation from Team User sub-accounts.

Servers that cannot immediately upgrade should review their mail delivery configuration for any options that force command execution (force_command) on locally-forwarded mail, and remove or disable them as a temporary workaround until the upgrade can be applied. Once the patch is applied, it would be safe to re-enable or reapply force_command.

Using command-line arguments intended for transferring queue-name through an Exim execution chain, files outside the spool area can be accessed. This can be used for a privilege escalation.

There is no known mitigation for this issue other than upgrading to a patched version of cPanel.