New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

Summary

cPanel has patched a critical vulnerability that allowed a hosting account with mail privileges to gain root access to an entire server. The flaw, identified as a way to create arbitrary files and then execute code as the root user, affected all supported versions of cPanel and WHM.

IFF Assessment

FOE

This vulnerability allows an attacker to gain complete control of a server, posing a significant threat to data and services.

Severity

9.8 Critical (AI Estimated)

This is a critical severity vulnerability (CVSS 9.8 - Critical) due to its high attack vector (Network access), high attack complexity (Low), privileges required (User, Mail Privileges), user interaction (None), and high impact on Confidentiality, Integrity, and Availability. The ability to run code as root means complete system compromise.

Defender Context

This vulnerability highlights the importance of timely patching for server management software like cPanel. Defenders should prioritize applying security updates to cPanel and WHM installations immediately to prevent exploitation. Server administrators should also review account privileges and monitor for any unusual file creation or process execution related to email services.

Read Full Story →