CVE-2016-10831 describes a critical authentication bypass vulnerability in cPanel versions prior to 55.9999.141, where the two-factor authentication check was not enforced when an attacker had already compromised one account and attempted to "possess" another. This flaw carries a CVSSv3 score of 7.2 (HIGH), indicating that an attacker with high privileges can exploit it over the network with low complexity to achieve high confidentiality, integrity, and availability impacts. There is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.54.0.0, < 11.54.0.20CPE matchmatch criteria | cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* | ||
>= 55.9999.61, < 55.9999.141CPE matchmatch criteria | cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.