Executive brief
A security flaw in the cPanel DNS Cluster system allows for the interception of sensitive data. Because the system fails to verify SSL certificates, a malicious actor could position themselves between servers to steal login credentials. This could lead to unauthorized access to hosting infrastructure and the compromise of customer data.
Technical details
The cPanel DNS Cluster system suffers from improper certificate validation (CWE-295) because SSL verification is explicitly disabled during communication. This vulnerability allows a network-positioned attacker to perform a man-in-the-middle (MitM) attack without requiring any prior authentication or user interaction. By intercepting the unverified connection, the attacker can capture sensitive credentials transmitted between cluster nodes. The issue was addressed in the May 13, 2026, security update for cPanel & WHM.
Affected products
- cPanel cPanel & WHM
Timeline
- 2026-05-13: disclosed
- 2026-05-13: patched
- 2026-05-13: advisory