CVE-2025-66429
cPanel vulnerability analysis and mitigation

Overview

CVE-2025-66429 is a directory traversal vulnerability in the cPanel Team Manager API that allows authenticated attackers with low-level privileges to overwrite arbitrary files, potentially enabling privilege escalation to the root user. It affects cPanel versions 110 through 132, with specific fixed versions available across multiple release branches. The vulnerability was published on December 11, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (Feedly, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The Team Manager API in cPanel fails to properly sanitize or restrict file path inputs, allowing an attacker to supply path traversal sequences (e.g., ../) to reference files outside the intended directory and overwrite them with attacker-controlled content. Because cPanel processes can operate with elevated privileges, overwriting sensitive system files (such as cron jobs, sudoers, or SSH authorized keys) can result in full root-level privilege escalation. No public proof-of-concept code has been identified at this time (Feedly, InfinitSec).

Impact

Successful exploitation allows an authenticated low-privileged user to overwrite arbitrary files on the server, with high impact to confidentiality, integrity, and availability. The most severe consequence is privilege escalation to the root user, which would grant complete control over the affected server, including access to all hosted websites, databases, email accounts, and system configurations. This could facilitate further lateral movement within a hosting environment, data exfiltration, or deployment of persistent backdoors (Feedly).

Exploitation steps

  1. Reconnaissance: Identify cPanel instances running versions 110–132 (specifically before 126.0.37, 130.0.16, or 132.0.4) via Shodan, Censys, or by inspecting cPanel login pages that expose version information.
  2. Obtain low-privileged access: Authenticate to the cPanel instance using any valid user account (e.g., a standard hosting account or team member account with access to the Team Manager API).
  3. Craft malicious API request: Formulate an API call to the Team Manager API endpoint that includes path traversal sequences (e.g., ../../etc/cron.d/malicious or ../../root/.ssh/authorized_keys) in a filename or path parameter intended to reference a team-related file.
  4. Overwrite target file: Submit the crafted request so that cPanel writes attacker-controlled content to the traversed path — for example, injecting a public SSH key into /root/.ssh/authorized_keys or adding a malicious cron job.
  5. Achieve privilege escalation: Use the overwritten file to gain root-level access — e.g., SSH into the server as root using the injected key, or wait for the malicious cron job to execute (Feedly, InfinitSec).

Indicators of compromise

  • Logs: cPanel API access logs showing Team Manager API requests with path traversal sequences (e.g., ../, %2e%2e%2f, or URL-encoded variants) in file path parameters; unexpected file write operations logged by the cPanel audit log outside of expected directories.
  • File System: Unexpected modifications to sensitive files such as /root/.ssh/authorized_keys, /etc/cron.d/*, /etc/sudoers, or web shell files placed in document roots; file timestamps inconsistent with normal administrative activity.
  • Network: Unusual SSH login attempts to the root account from new or unknown IP addresses following API activity; unexpected outbound connections from the server to external hosts.
  • Process: Unexpected cron job executions or processes spawned as root that are not associated with normal cPanel operations.

Mitigation and workarounds

cPanel has released patched versions addressing this vulnerability: 126.0.37 (for the 110–126 branch), 130.0.16 (for the 128–130 branch), and 132.0.4 (for the 132 branch). Administrators should update to the appropriate patched version immediately using the cPanel update mechanism. As interim mitigations, restrict access to the Team Manager API to trusted users only, monitor API access logs for suspicious path traversal patterns, and audit sensitive system files for unauthorized modifications (Feedly, cPanel Release Notes).

Community reactions

The vulnerability received moderate community attention following its December 2025 disclosure, with discussions appearing on Reddit's r/cybersecurity and r/blueteamsec communities, as well as on Bluesky (Reddit r/cybersecurity, Reddit r/blueteamsec). Security researchers noted the severity of the privilege escalation potential given cPanel's widespread use in shared hosting environments. No major vendor statements beyond the cPanel changelog have been identified.

Additional resources


SourceThis report was generated using AI

Related cPanel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-41940CRITICAL9.3
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
YesYesApr 29, 2026
CVE-2025-66429HIGH8.8
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesDec 11, 2025
CVE-2021-38589HIGH8.1
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesAug 11, 2021
CVE-2023-29489MEDIUM6.1
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesApr 27, 2023
CVE-2021-38590MEDIUM5.5
  • cPanel logocPanel
  • cpe:2.3:a:cpanel:cpanel
NoYesAug 11, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management