CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6805

As cited

Copy frozen at (site build).

vulnerabilities

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a vulnerability affecting all supported versions that allows an authenticated hosting account with mail privileges to create arbitrary files on the server through EmailTrack and execute code as root. The flaw enables a single account holder to gain complete control of the entire server.

Why it matters: Hosting providers and cPanel administrators must prioritize patching immediately, as any customer account with mail privileges can escalate to full server compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary