New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

Summary

A critical vulnerability in cPanel's CalDAV and CardDAV service allows any hosting account holder to execute code as root and gain complete server control. Additionally, a separate bug in the WP Toolkit plugin enables account holders to alter databases belonging to other users. cPanel has since released patches for both issues.

IFF Assessment

FOE

This vulnerability allows attackers to gain root access and full control over servers, posing a significant threat to data and infrastructure.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for remote code execution with elevated privileges (root) and complete server control, which is a critical impact. The ease of exploitation for an account holder makes it highly dangerous.

Defender Context

This incident highlights the critical need for timely patching of server management software like cPanel. Defenders should prioritize updates for cPanel and any associated plugins, and implement robust access control measures to limit the blast radius of potential compromises.

Read Full Story →