Executive brief
A security flaw in cPanel & WHM allows a standard team member to bypass security checks and take over the team owner's account. This could lead to unauthorized access to sensitive server management tools and full control over the affected hosting environment. Organizations using these tools should apply the available security updates to prevent internal users from gaining excessive administrative power.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in cPanel & WHM's team management functionality. The application fails to properly validate the permission levels of team members during specific administrative actions, allowing a low-privileged user to escalate their privileges to those of a team owner. This is a network-based attack that requires basic user authentication (PR:L) but no user interaction. The vulnerability was addressed in the security update released on May 13, 2026.
Affected products
- cPanel cPanel & WHM
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory: cPanel released a security update for this issue.