High SEVERITY — Vulnerability

CVE-2025-66429 — An issue was discovered in cPanel 110 through 132.

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

Platform
cPanel & WHM
CVE Record
CVE-2025-66429
CVSS Score
8.8/10
Published
11 December 2025
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Summary

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

Assessment

  • CVE: CVE-2025-66429
  • CVSS base score: 8.8
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Source: NVD entry

References

Actions

  • Verify affected systems in inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until the patch is applied
cpanel *

cPanel & WHM — Related Advisories

VIEW ALL →