By Interestana AI Editorial — AI-drafted, human-overseen. How we report
cPanel Patches Critical Flaw Allowing Root Access Via Mail Feature

cPanel has issued a patch for a critical security vulnerability that allowed an authenticated user with mail-related privileges to gain complete control of a server. The flaw, detailed in an advisory published on September 8, enables an account holder to create arbitrary files on the server through the EmailTrack feature. Once files are created, the attacker can then execute code with root user privileges, effectively compromising the entire server.
This vulnerability affects all supported versions of cPanel and WHM, the company's web hosting control panel and its server administration counterpart. The exploit chain begins with an attacker who already possesses authenticated access to a hosting account and has been granted mail-related privileges. By leveraging the EmailTrack functionality, which is designed to track email delivery and performance, the attacker can manipulate the system to write malicious files to specific locations on the server. The ability to create these files is the crucial first step in escalating privileges.
Following the creation of these files, the attacker can then proceed to execute arbitrary commands as the root user. Root access is the highest level of privilege on a Linux-based operating system, granting the user unrestricted control over the system. This means an attacker could install malware, steal sensitive data, modify system configurations, or even launch further attacks from the compromised server. The advisory from cPanel emphasizes the severity of this exploit, highlighting the potential for widespread damage if left unaddressed.
cPanel, a widely used web hosting control panel, provides a graphical interface that simplifies server administration for web hosting providers and their customers. WHM (WebHost Manager) is a more powerful tool designed for server administrators to manage multiple cPanel accounts, perform server-wide tasks, and monitor server health. The widespread adoption of these products means that a significant number of web servers globally were potentially exposed to this vulnerability until the patch was applied. The company's prompt action in releasing an advisory and a fix is crucial for mitigating the risk to its user base. Users are strongly advised to update their cPanel and WHM installations to the latest versions to ensure they are protected against this critical security threat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.