Bought one hosting account and got root over neighbors. cPanel urgently closed the critical hole

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
442
Reaction score
719
Deposit
0$
One regular account on shared hosting could give the owner control over the entire server. CPEEL & WHM found a critical vulnerability of CVE-2026-65643, which allowed the local user to achieve arbitrary code with root rights and potentially access sites, databases and other clients’ accounts.

The problem was in the carving mechanism of cPanel domains. For the attack, the attacker required a valid cPanel account with permission to add parked domains or addon domains. This possibility is often available to ordinary virtual hosting clients and does not in itself assume administrative privileges.

Due to the error, the user could force the system to create arbitrary files on the server. Further operation allowed to move from the rights of the ordinary client to the execution of commands on behalf of root, that is, to get maximum privileges in the system.

For shared hosting, such a scenario is particularly dangerous. One physical or virtual server can operate dozens or hundreds of sites of different clients at the same time. Having received root access, the attacker is potentially able to read and modify the files of neighboring accounts, steal the contents of databases, receive credentials, implement malicious code and use the server for further attacks.


cPanel reported the vulnerability on August 27 and issued fixes for all supported cPanel & WHM branches. Server administrators are advised to install up-to-date builds as soon as possible, since one compromised user account, if the necessary permissions are available, is enough to attack the entire machine.

On the forum cPanel, one of the users said that he was faced with a hacking of the server on August 25, two days before the publication of the bulletin. The communicant links the incident to a new vulnerability, but there is no independent confirmation of such a link. Data on the mass operation of CVE-2026-65643 in real attacks cPanel also did not result.

The vulnerability is particularly unpleasant because it is not necessary to crack the administrative panel or get root access in advance to launch the attack. It is enough for a potential attacker to be a regular hosting client with the ability to add additional or parked domains. In the shared hosting infrastructure, this level of access is found everywhere, so delaying the update can jeopardize all users of a vulnerable server at once.
 
Top Bottom