A critical flaw in the widely-deployed cPanel & WHM server management platform allows any user with a basic hosting account to execute code as the root user, effectively granting complete control over an entire server. Disclosed on September 22, this vulnerability poses an immediate, severe risk, particularly for shared hosting environments.

The primary vulnerability resides in cPanel's CalDAV and CardDAV service, which manages calendar and contact data. An attacker with a standard hosting account can exploit this flaw to bypass security restrictions and gain unrestricted root access. In a multi-tenant setting, this means a single compromised account could lead to the takeover of every site and account hosted on the same physical server.

A second high-severity bug in the popular WP Toolkit plugin, used for installing and managing WordPress sites, was also patched. This flaw allows one account holder to access and modify databases belonging to other, separate accounts on the same server, enabling cross-account data theft or manipulation.

Both flaws represent a fundamental breakdown of the isolation security principle expected in hosting platforms. cPanel has released fixed versions for all supported software tiers and is strongly urging all administrators to update without delay.

Immediate Actions for Administrators

System administrators and hosting providers should implement the following steps urgently:

  1. Apply Patches Immediately: Log in to WHM, navigate to the update interface, and install the latest available version for your cPanel & WHM release tier.
  2. Investigate Suspicious Activity: If immediate patching is not possible, audit server and access logs for unusual activity originating from any cPanel account. Look for unexpected command executions or file access.
  3. Audit Account Permissions: Conduct a review of user privileges in shared hosting environments, ensuring no account holds unnecessary permissions.
  4. Consider Interim Mitigation: As a temporary measure to reduce the attack surface, administrators could disable the CalDAV and CardDAV service until a full patch can be applied.

A successful attack exploiting these flaws could lead to extensive data breaches, website defacement, or the server being hijacked for malicious activities like botnet inclusion. Given the low barrier to exploit—requiring only an existing account—any system running an unpatched version of cPanel must be treated as an active emergency.


廣泛部署的cPanel & WHM伺服器管理平台出現一個嚴重漏洞,允許任何擁有基本主機託管帳戶的使用者以最高用戶(root)身份執行代碼,實際上獲得對整個伺服器的完全控制權。該漏洞於9月22日披露,構成即時且嚴重的風險,尤其對於共享主機環境而言。

主要漏洞存在於cPanel的CalDAV與CardDAV服務中,該服務用於管理日曆及聯絡人資料。擁有標準主機託管帳戶的攻擊者可利用此漏洞繞過安全限制,獲得不受限的最高用戶訪問權限。在多租戶環境中,這意味著一個被入侵的帳戶可能導致同一實體伺服器上託管的所有網站和帳戶被接管。

另一個針對用於安裝及管理WordPress網站的熱門WP Toolkit外掛程式的嚴重漏洞亦已修補。該漏洞允許一個帳戶持有者訪問並修改同一伺服器上其他獨立帳戶的資料庫,從而實現跨帳戶的資料竊取或篡改。

這兩個漏洞均代表託管平台預期的隔離安全原則出現根本性失效。cPanel已為所有支援的軟件版本發布修補版本,並強烈敦促所有管理員毫不延遲地進行更新。

管理員即時應對措施

系統管理員與主機託管供應商應緊急執行以下步驟:

  1. 立即套用修補程式: 登入WHM,前往更新介面,安裝適用於您的cPanel & WHM版本層級的最新可用版本。
  2. 調查可疑活動: 若無法立即進行修補,應審核伺服器及訪問日誌,檢查來自任何cPanel帳戶的異常活動。留意未預期的指令執行或檔案訪問。
  3. 審計帳戶權限: 在共享主機環境中審查用戶權限,確保沒有帳戶持有不必要的權限。
  4. 考慮過渡緩解措施: 作為減少攻擊面的臨時措施,管理員可在套用完整修補程式前停用CalDAV與CardDAV服務。

成功利用這些漏洞進行攻擊,可能導致大規模資料洩露、網站頁面被篡改,或伺服器被劫持用於惡意活動(如納入殭屍網絡)。鑒於攻擊所需的低門檻——僅需一個現有帳戶——任何運行未修補版本cPanel的系統都必須視為緊急事件處理。

新聞來源 / Original News Source