$ techbeacon▋
CVE & Exploits

cPanel Issues Patches for Critical WHM Flaws Allowing Root Access and Session Hijacking

cPanel Issues Patches for Critical WHM Flaws Allowing Root Access and Session Hijacking

cPanel Inc. has rolled out emergency updates to fix three serious vulnerabilities discovered in its cPanel and WHM platforms, flaws that could let attackers seize WHM administrator sessions or run commands with root privileges.

The security advisory, first highlighted by the security research outlet GBHackers, warns that the weaknesses affect a range of cPanel deployments still running pre‑update versions. Exploitation of these bugs could give a malicious actor full control over a server, compromising both hosted websites and the underlying operating system.

cPanel, a dominant control panel for shared hosting environments, routinely publishes patches to address emerging threats. In this case, the vulnerabilities stem from inadequate validation of session tokens and insufficient sandboxing of certain privileged operations. While the exact technical details are reserved for the official advisory, the vendor stresses that the flaws permit arbitrary code execution as the root user and enable hijacking of active admin sessions, effectively bypassing authentication mechanisms.

System administrators are urged to apply the newly released updates without delay. The company’s documentation outlines a straightforward upgrade path through the built‑in update manager or via command‑line tools for larger infrastructures. Failure to patch promptly could expose servers to automated attacks, as exploit code often spreads quickly once publicly disclosed.

Industry analysts note that the timing of the patches underscores the ongoing cat‑and‑mouse dynamic between hosting platforms and threat actors. cPanel’s large install base makes it a lucrative target, and the discovery of multiple high‑impact bugs in a single release is a reminder of the importance of regular maintenance and security hygiene in web‑hosting environments.

Looking ahead, cPanel has pledged to continue monitoring for related issues and to enhance its security testing processes. Organizations that rely on cPanel and WHM are advised to review their broader security posture, including firewall rules, intrusion detection systems, and regular credential audits, to mitigate the risk of similar vulnerabilities emerging in the future.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related