cPanel Vulnerability Allows Hosting Accounts to Execute Code as Root, Gain Full Server Control
What Happened — A flaw in cPanel’s CalDAV and CardDAV services lets any account with a cPanel hosting login execute code with root privileges, effectively taking full control of the underlying server. A second issue in the WP Toolkit plugin permits an account holder to modify databases belonging to other customers. cPanel has issued patched versions for both components.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk when privileged access is not properly isolated – a core access control and privilege management objective that continuous‑control programs must monitor and evidence.
- Highlights the need for configuration‑management evidence to prove that software components are kept up‑to‑date and that segregation controls are enforced.
- Aligns with Verisq’s Control Mapping capability, which helps organizations collect, map, and continuously verify evidence that such controls are operating as intended.
Who Is Affected
- Web‑hosting providers and managed service providers that deploy cPanel.
- SaaS platforms that rely on cPanel for customer site provisioning.
- End‑customers whose sites are hosted on vulnerable instances.
Recommended Actions
- Deploy the latest patched cPanel releases immediately across all servers.
- Conduct a privileged‑access review to confirm that no account retains unnecessary root rights.
- Verify that isolation controls (e.g., containerization, chroot jails) are enforced and documented as evidence.
- Update your control‑mapping inventory to reflect the new version status and any remediation steps taken.
- Enable continuous monitoring for anomalous root‑level activity and retain logs as audit‑ready evidence.
Source: The Hacker News
Technical Notes
- Attack Vector: Exploitation of CalDAV/CardDAV service logic flaw; cross‑account database manipulation via WP Toolkit plugin.
- Impact: Potential full server compromise, lateral movement across hosted accounts, and data exposure.
- Patch Status: Fixed versions released by cPanel; no CVE identifier disclosed publicly at time of reporting.
Source: The Hacker News