news.mlab.sh
Back to the feed
vulnerability

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Critical
Summary

A critical security vulnerability in cPanel and WebHost Manager (WHM) allows an authenticated user adding parked or addon domains to execute code as the root user, potentially leading to full server control. While the vulnerability has not yet been confirmed exploited, it's present in end-of-life versions and requires immediate patching. The vulnerability stems from a flaw in the Passenger package and has been linked to ransomware campaigns.

A critical security vulnerability exists within cPanel and WebHost Manager (WHM), impacting all supported versions. This flaw allows an authenticated user who can add parked or addon domains to create arbitrary files on the server, ultimately leading to code execution as the root user and full server control. cPanel has released patched versions including 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and 11.138.1.7 (WP Squared). The vulnerability is linked to a flaw in the Passenger package and has been associated with ransomware campaigns, with a CVE-2026-41940 previously exploited in such campaigns. cPanel has not yet confirmed whether the vulnerability has been exploited, and it is not currently listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog. Plesk, which develops alongside cPanel, has also released an advisory and a checklist for identifying prior compromise. Administrators should immediately apply the latest patches by logging in to the server as root and running /scripts/upcp --force, or through WHM under Home > cPanel > Upgrade to Latest Version. Servers running end-of-life versions must be upgraded to a supported version to receive the fix.

Read the full article at The Hacker News