Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in cPanel/WHM

Multiple vulnerabilities in cPanel/WHM allow remote attackers to manipulate files and escalate privileges, potentially leading to arbitrary code execution with administrative rights.

The German Federal Office for Information Security (BSI) has reported multiple security vulnerabilities affecting cPanel/WHM installations. These flaws enable an unauthenticated or low-privileged attacker to perform arbitrary file manipulation and gain elevated privileges on the underlying host. Successful exploitation of these vulnerabilities may allow the execution of arbitrary code with administrative privileges. Given the nature of cPanel as a web hosting control panel, which typically runs with root-level access to manage system services and user accounts, these vulnerabilities represent a significant risk to the integrity and confidentiality of the host environment. Defenders should prioritize patching and monitoring for unauthorized file system modifications within the cPanel/WHM directories.

Impact

Successful exploitation allows attackers to gain full administrative control over the cPanel/WHM server. This results in complete compromise of all hosted websites, databases, email services, and server configuration settings. Impacted sectors include web hosting providers and organizations managing their own web infrastructure.

Recommendation

  • Monitor file integrity for critical cPanel configuration and binary paths.
  • Review all system access logs for signs of privilege escalation or unusual administrative commands executed via the cPanel web interface.
  • Apply the latest security updates provided by cPanel LLC immediately to remediate the identified vulnerabilities.

Immediate actions

Update cPanel/WHM instances to the latest available version.

IT Operations 24h

Threat Hunt

Unauthorized modification of system binaries or configuration files within /usr/local/cpanel/.

T1068 high medium confidence hunt now

Data: File integrity monitoring logs

Mitigations

Apply security updates.

immediate IT Operations

Multiple vulnerabilities in cPanel/WHM