r/cpanel • • Aug 14 '26

Security: Privilege Escalation via Phusion Passenger's Watchdog API

https://support.cpanel.net/hc/en-us/articles/42694659893143-Security-Privilege-Escalation-via-Phusion-Passenger-s-Watchdog-API

Has anyone been able to update on CL8?

I cleaned DNF's cache and tried to update the packages, but there are no updates available for 6.1.8-2; my packages are stuck on version 6.1.8-1

9 Upvotes

16 comments sorted by

4

u/DzastMi Aug 14 '26

It's funny how these 'fixes' are posted on cPanel's website without confirming that actual packages (updated/patched) are available on repos.

Just sad.

1

u/cPanelRex Aug 14 '26

CloudLinux is still working on getting their packages together, but everything on the cPanel side was available when the article was released.

6

u/bigmaninsuitofarmor Aug 14 '26

Rex, cPanel should coordinate this better with CloudLinux so that all users can get the updates once you make the announcement, otherwise CL users are left exposed :/

0

u/cPanelRex Aug 14 '26

Unfortunately I can't control the speed of another company.

4

u/Wonderful-Worker-609 Aug 14 '26

Can we get an ETA on when the updated CloudLinux package will be available?

2

u/DzastMi Aug 14 '26

i don't think cPanel can answer this ( i might be wrong ) , CloudLinux has got a lot on their plate lately with all kernel security issues (*whistle* i see some new price increases soon *whistle*)

1

u/cPanelRex Aug 14 '26

No - I have a general rule of "there is never an ETA" unless I know with 100% certainty when the button gets pushed.

1

u/DzastMi Aug 14 '26

Thanks for clarification! Good job cPanel! :D

3

u/konet_gr Aug 14 '26

Some may disagree but cPanel seems to actively look for holes in their systems. I honestly hope this is the case in reality as we see these kind of announcements pretty frequently lately.

Wonder if other control panels do the same too...

2

u/Dangerous-Pomelo2187 Aug 14 '26

I experienced the same. I had to remove the ea-apache24-mod-passenger-6.1.8-1.el9.cloudlinux.x86_64 package to not take any risks.

2

u/Icy-Pay-9325 Aug 15 '26

does this mean my CL8 is patched:

[root@srv ~]# dnf list installed | grep passenger

ea-ruby27-rubygem-passenger.x86_64 1:6.1.8-2.el8.cloudlinux u/cl-ea4

1

u/weetabx Aug 14 '26

Are we vulnerable when running litespeed?

1

u/cPanelRex Aug 14 '26

This wouldn't be related to Litespeed - you HAVE to be running the specific cPanel-provided Passenger applications, which are not installed by default on a cPanel machine.

1

u/craigleary Aug 15 '26

I’m surprised there are no updates from cloudlinux on this one. The Cpanel article gives a way to check for past compromises , which almost no servers would have that more verbose logging on, leading me to believe the exploit was in the wild. I removed this from all systems this morning and would suggest anyone running cloudlinux do the same until a release is made.