Critical cPanel Vulnerability Exposes User Accounts
Key Takeaways A series of critical vulnerabilities, including multiple CVEs and a LiteSpeed Enterprise flaw, have been identified in cPanel & WHM. These security gaps could allow attackers to...
Key Takeaways
- A series of critical vulnerabilities, including multiple CVEs and a LiteSpeed Enterprise flaw, have been identified in cPanel & WHM.
- These security gaps could allow attackers to compromise user accounts and potentially entire hosting servers.
- The most severe vulnerabilities carry CVSS scores up to 9.8, indicating critical severity.
- Patches are available, and immediate updates are strongly recommended for all affected systems.
Critical Flaws Discovered in cPanel & WHM, Threatening Hosting Environments
Multiple significant security vulnerabilities have been uncovered in cPanel & WHM, a widely used web hosting automation platform. These flaws, identified by various researchers and assigned several CVEs, pose a substantial risk to user accounts and the integrity of entire hosting servers. The vulnerabilities range in severity, with some achieving critical CVSS scores.
Table Of Content
Details of the Vulnerabilities
Among the critical issues are CVE-2026-68490, CVE-2026-87899, and CVE-2026-87900, all of which received a CVSS score of 9.8, categorizing them as critical. These vulnerabilities were discovered by security researcher Piotr Gasiorowski. Two additional high-severity flaws, CVE-2026-65638 and CVE-2026-67401, both with a CVSS score of 8.8, were reported by Assetnote. Another significant vulnerability, CVE-2026-65643, was reported by RCE Security and also carries a CVSS score of 8.8.
Beyond these CVEs, a separate critical flaw affecting LiteSpeed Enterprise, a web server often used in conjunction with cPanel, was addressed in version 6.3.7. This particular vulnerability could allow for remote code execution (RCE), enabling an attacker to fully compromise the server. It was identified by RCE Security, who published their findings on June 10, 2024.
Potential Impact and Urgency of Patching
The collective impact of these vulnerabilities is severe. A successful exploit of even a single compromised hosting account could lead to unauthorized access to adjacent tenant accounts on the same server. In the most critical scenarios, an attacker could gain full control over the entire hosting server, leading to data breaches, service disruption, and further malicious activities. Given the widespread deployment of cPanel & WHM, the potential for broad exploitation underscores the urgency for system administrators to apply the available patches without delay.
What You Should Do
- Immediately Update cPanel & WHM: Apply all available patches and updates for your cPanel & WHM installations to address the identified CVEs.
- Update LiteSpeed Enterprise: If you are running LiteSpeed Enterprise, ensure it is updated to version 6.3.7 or newer to mitigate the RCE vulnerability.
- Review Access Logs: Monitor server and application logs for any suspicious activity that might indicate an attempted or successful exploit.
- Implement Least Privilege: Ensure that all user accounts and services operate with the minimum necessary permissions to limit potential damage from a compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.