Executive brief
A vulnerability in the cPanel Nova plugin allows an authorized user to gain administrative control over the entire server. By creating a malicious link within their own directory, a user can trick the system into changing the permissions of critical system files. This can lead to a total system takeover, data theft, or a complete shutdown of services.
Technical details
The vulnerability is a symbolic link (symlink) following issue (CWE-61) within the Cpanel::Nova::Connector component of the cPanel Nova plugin. The root cause is an insecure 'chmod' operation that fails to validate if the target path is a symlink before execution. An authenticated cPanel user can exploit this by placing a symlink at a specific legacy Nova path within their home directory that points to a sensitive system file or directory. When the plugin performs its routine operations, it follows the symlink and applies permission changes to the target file with root privileges. This allows the attacker to achieve local privilege escalation or cause a Denial of Service (DoS) by corrupting system file permissions. cPanel has released a security update to address this issue.
Affected products
- cPanel Nova plugin
Timeline
- 2026-05-08: advisory: Initial disclosure by cPanel and NVD publication