PT-2026-82649 · Cpanel · Cpanel+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cPanel & WHM versions prior to 11.110.0.141
cPanel & WHM versions prior to 11.134.0.53
cPanel & WHM versions prior to 11.136.0.37
cPanel & WHM versions prior to 11.138.0.2
WP Squared versions prior to 11.138.1.7
Description
An eval injection and arbitrary file write flaw exists in the domain parking and addon domain functionality. An authenticated user with permissions to manage these domains can create arbitrary files on the underlying server, leading to privilege escalation and remote code execution as root. This allows a low-privileged account holder to bypass hosting security boundaries and gain full control over the entire server, including all hosted accounts, databases, and configuration files.
Recommendations
Update cPanel & WHM to version 11.110.0.141 or later.
Update cPanel & WHM to version 11.134.0.53 or later.
Update cPanel & WHM to version 11.136.0.37 or later.
Update cPanel & WHM to version 11.138.0.2 or later.
Update WP Squared to version 11.138.1.7 or later.
As a temporary workaround, disable the Park Domain and Addon Domain features in the WHM Feature Manager for non-admin users.
Administrators can force an update by running the
/scripts/upcp --force command.Fix
LPE
RCE
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Whm
Cpanel