CVE-2025-66429

8.8

cPanel · cPanel

A directory traversal vulnerability in the cPanel Team Manager API allows authenticated users to overwrite arbitrary files, potentially leading to root privilege escalation.

Executive summary

A high severity directory traversal vulnerability in cPanel versions 110 through 132 poses a critical risk of unauthorized root privilege escalation.

Vulnerability

This is a directory traversal vulnerability located within the Team Manager API. The flaw allows an authenticated user to perform arbitrary file overwrites, which can be leveraged to achieve full root level access.

Business impact

The ability for an authenticated user to overwrite arbitrary system files and escalate privileges to root represents a total compromise of the affected server. Given the CVSS score of 8.8, this vulnerability carries significant risk for data integrity, confidentiality, and system availability. Organizations should treat this as a high priority threat to prevent unauthorized administrative control.

Remediation

Immediate Action: Update all cPanel installations to the latest patched version as specified in the official cPanel release notes.

Proactive Monitoring: Review web server access logs for unusual requests targeting the Team Manager API or unexpected file modification patterns.

Compensating Controls: Ensure that access to the cPanel interface is restricted to trusted IP addresses and enforce strong multi-factor authentication for all user accounts to prevent unauthorized access to the vulnerable API.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or weaponized module available in the provided data.

Analyst recommendation

The severity of this vulnerability, combined with the potential for full system takeover, necessitates immediate action. Administrators must verify their current cPanel version and apply security patches provided by the vendor without delay. Failure to remediate this flaw leaves the underlying infrastructure exposed to complete administrative compromise.

More cPanel CVEs

Sources