
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66429 is a directory traversal vulnerability in the cPanel Team Manager API that allows authenticated attackers with low-level privileges to overwrite arbitrary files, potentially enabling privilege escalation to the root user. It affects cPanel versions 110 through 132, with specific fixed versions available across multiple release branches. The vulnerability was published on December 11, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (Feedly, Red Hat CVE).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The Team Manager API in cPanel fails to properly sanitize or restrict file path inputs, allowing an attacker to supply path traversal sequences (e.g., ../) to reference files outside the intended directory and overwrite them with attacker-controlled content. Because cPanel processes can operate with elevated privileges, overwriting sensitive system files (such as cron jobs, sudoers, or SSH authorized keys) can result in full root-level privilege escalation. No public proof-of-concept code has been identified at this time (Feedly, InfinitSec).
Successful exploitation allows an authenticated low-privileged user to overwrite arbitrary files on the server, with high impact to confidentiality, integrity, and availability. The most severe consequence is privilege escalation to the root user, which would grant complete control over the affected server, including access to all hosted websites, databases, email accounts, and system configurations. This could facilitate further lateral movement within a hosting environment, data exfiltration, or deployment of persistent backdoors (Feedly).
../../etc/cron.d/malicious or ../../root/.ssh/authorized_keys) in a filename or path parameter intended to reference a team-related file./root/.ssh/authorized_keys or adding a malicious cron job.../, %2e%2e%2f, or URL-encoded variants) in file path parameters; unexpected file write operations logged by the cPanel audit log outside of expected directories./root/.ssh/authorized_keys, /etc/cron.d/*, /etc/sudoers, or web shell files placed in document roots; file timestamps inconsistent with normal administrative activity.cPanel has released patched versions addressing this vulnerability: 126.0.37 (for the 110–126 branch), 130.0.16 (for the 128–130 branch), and 132.0.4 (for the 132 branch). Administrators should update to the appropriate patched version immediately using the cPanel update mechanism. As interim mitigations, restrict access to the Team Manager API to trusted users only, monitor API access logs for suspicious path traversal patterns, and audit sensitive system files for unauthorized modifications (Feedly, cPanel Release Notes).
The vulnerability received moderate community attention following its December 2025 disclosure, with discussions appearing on Reddit's r/cybersecurity and r/blueteamsec communities, as well as on Bluesky (Reddit r/cybersecurity, Reddit r/blueteamsec). Security researchers noted the severity of the privilege escalation potential given cPanel's widespread use in shared hosting environments. No major vendor statements beyond the cPanel changelog have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."