חזרה לפיד
newsמקור: The Hacker News9.9.2026

פרצת אבטחה חדשה ב-cPanel: חשבון אירוח עם הרשאות מייל יכול להריץ קוד כ-Root

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

פרצת אבטחה חדשה ב-cPanel: חשבון אירוח עם הרשאות מייל יכול להריץ קוד כ-Root

◆ סיכום AI

cPanel תיקנה פגיעות חמורה המאפשרת לחשבון אירוח בודד עם הרשאות מייל (דרך EmailTrack) ליצור קבצים בשרת ולהריץ קוד בתור משתמש Root. פרצה זו משפיעה על כל הגרסאות הנתמכות של cPanel ו-WHM ומאפשרת השתלטות מלאה על השרת. משתמשים נדרשים לעדכן בדחיפות.

# מהמקור

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

#cpanel#privilege-escalation#rce#hosting-security
קרא במקור