Executive brief
A security vulnerability exists in cPanel & WHM, a popular web hosting control panel used to manage websites and server configurations. An attacker with an existing low-privileged account can exploit a flaw in the user creation process to run unauthorized commands on the server. This could allow an attacker to gain full control over their hosting environment, potentially leading to data theft or service disruption.
Technical details
A code injection vulnerability (CWE-94) exists in the cPanel & WHM 'create_user' plugin. The vulnerability stems from insufficient validation of the 'plugin' parameter, which allows an authenticated attacker to inject and execute arbitrary Perl code. The code executes with the privileges of the authenticated account's system user. While the attack requires network access and valid low-level credentials (PR:L), it allows for a complete compromise of confidentiality, integrity, and availability for the affected user's environment. A security update was released by cPanel on May 8, 2026, to address this issue.
Affected products
- cPanel cPanel & WHM
Timeline
- 2026-05-08: advisory: Initial disclosure and cPanel security update published
- 2026-05-08: disclosed: CVE published to NVD dataset