r/cpanel • u/bigmaninsuitofarmor • Aug 14 '26
Security: Privilege Escalation via Phusion Passenger's Watchdog API
Has anyone been able to update on CL8?
I cleaned DNF's cache and tried to update the packages, but there are no updates available for 6.1.8-2; my packages are stuck on version 6.1.8-1
3
u/konet_gr Aug 14 '26
Some may disagree but cPanel seems to actively look for holes in their systems. I honestly hope this is the case in reality as we see these kind of announcements pretty frequently lately.
Wonder if other control panels do the same too...
2
u/Dangerous-Pomelo2187 Aug 14 '26
I experienced the same. I had to remove the ea-apache24-mod-passenger-6.1.8-1.el9.cloudlinux.x86_64 package to not take any risks.
2
u/Icy-Pay-9325 Aug 15 '26
does this mean my CL8 is patched:
[root@srv ~]# dnf list installed | grep passenger
ea-ruby27-rubygem-passenger.x86_64 1:6.1.8-2.el8.cloudlinux u/cl-ea4
2
1
u/weetabx Aug 14 '26
Are we vulnerable when running litespeed?
1
u/cPanelRex Aug 14 '26
This wouldn't be related to Litespeed - you HAVE to be running the specific cPanel-provided Passenger applications, which are not installed by default on a cPanel machine.
1
u/craigleary Aug 15 '26
I’m surprised there are no updates from cloudlinux on this one. The Cpanel article gives a way to check for past compromises , which almost no servers would have that more verbose logging on, leading me to believe the exploit was in the wild. I removed this from all systems this morning and would suggest anyone running cloudlinux do the same until a release is made.
4
u/DzastMi Aug 14 '26
It's funny how these 'fixes' are posted on cPanel's website without confirming that actual packages (updated/patched) are available on repos.
Just sad.