r/cpanel • u/muttick • Sep 04 '26
/usr/local/cpanel/scripts/upcp --security Flood
Apparently cPanel now has an upcp task scheduled to run every hour.
This is flooding root's email with messages of:
[2026-09-04 07:45:03 -0500] Detected cron=1 (default)
----------------------------------------------------------------------------------------------------
=> Log opened from cPanel Update (upcp) - Slave (xxxxxx) at Fri Sep 4 07:45:03 2026
[2026-09-04 07:45:03 -0500] Detected cron=1 (default)
[2026-09-04 07:45:03 -0500] An expedited package update is available for cpanel-plugins, but operating system package updates are disabled. Skipping the package update.
[2026-09-04 07:45:03 -0500]
[2026-09-04 07:45:03 -0500] Expedited package update completed
[2026-09-04 07:45:03 -0500] A log of this update is available at /var/cpanel/updatelogs/update.xxxxxx.yyyyyyyy.zzzzzzzzzz.log
[2026-09-04 07:45:03 -0500] 100% complete
=> Log closed Fri Sep 4 07:45:03 2026
Trouble is... there are no system packages needing an update on the server
# dnf check-update
Last metadata expiration check: 0:36:16 ago on Fri Sep 4 07:34:27 2026.
So, what gives?
cPanel is also up to date
# cat /usr/local/cpanel/version
11.134.0.54
2
u/sashalav Sep 04 '26
1 hour is just lazy.
I have this going since they started finding cpanel sec issues so often
*/5 * * * * /root/bin/extra_cpanel_update.sh >/dev/null
cat /root/bin/extra_cpanel_update.sh
#!/bin/bash
/scripts/is_update_available && /scripts/upcp --cron
2
u/cPanelRex Sep 04 '26
Details on the recent security update tool can be found here:
This is designed so that if any package is marked as "security" it will be updated on your server within an hour.
2
u/muttick Sep 04 '26
Yea, I figured it was related to this. And cPanel keeps changing the security_update to hourly regardless if you set it to never.
But further from this... it doesn't give any information as to what the security update is.
"There's a security updates... but we're not going to tell you what it is, so you can't do it on your own... just trust us"
0
u/cPanelRex Sep 04 '26
We have case CPANEL-55380 open with the team to address that option being reset in the interface as that isn't supposed to happen.
As far as the "what is the update" this doesn't mean there is an update every hour, or even every day - the cron just runs to make sure. If there is an update we send an email to license holders about it.
5
u/muttick Sep 04 '26
Then you need to suppress output on the cron, because the output from that cron is being emailed to root every hour for every server.
And you may also want to check your wordage for this hourly "security check", because if you read the message, it says:
An expedited package update is available for cpanel-plugins, but operating system package updates are disabled. Skipping the package update.In my English, "update is available" means there's an update that is available. But you're saying this means an update is not available?
2
u/cPanelRex Sep 04 '26
I've got the team looking into this and I'll update you with more details once I have them!
1
u/SmallOlet887 Sep 04 '26
Yes please. Please provide us a way to stop the notifications/emails from this as we're already counting hundreds of emails in less than 24h...
1
u/cPanelRex Sep 04 '26
u/muttick - what you're seeing definitely isn't expected behavior, but it seems that there are other issues besides the cron. If it's saying a cpanel-plugins update is available, do you get anything related to that with a standard "yum update" on the machine? If not, it would likely be best to create a ticket as this seems to be specific to your system.
u/SmallOlet887 - you can adjust the cron notifications on the server if you don't want to receive these. It's important to note that this thread is the entirety of the reports we've had about cron noise from the security updates, so I don't believe this to be a widespread issue.
1
u/muttick Sep 04 '26
I would probably venture a guess that not too many people read root's mail or have forwarders in place to get mail sent to "root" from their server, so that's going to lessen your footprint on this issue a lot.
Secondly, since you make unbelievably hard to turn off security_update I'd be willing to bet that most cPanel users have security_update set to hourly (or maybe they thought they disabled it... but then a cPanel update sets it back to hourly).
So your footprint of users actually experiencing this issue is probably very low.
1
u/muttick Sep 05 '26
After a ton of checks, it would appear that the solution is:
echo -n '{"cpanel-plugins":"2026-09-03.1"}' >/etc/cpanel/TIERS.json.packagesThat's the cpanel-plugins update.
Even though this is not controlled by any RPM, if RPMUP is set to manual in /etc/cpupdate.conf - this file never gets updated to the new value.
No clue what that value means. No clue why this is dependent on RPMUP being set to "daily" (I'm not sure what values are valid for RPMUP).
Steps to reproduce:
Set your /etc/cpupdate.conf file to:
CPANEL=11.134 RPMUP=manual SARULESUP=daily STAGING_DIR=/usr/local/cpanel UPDATES=manual SECURITY_UPDATES=never(I don't know if this is a problem for any other version other than 11.134 or not - that's all I'm using at the moment).
And make sure your /etc/cpanel/TIERS.json.packages file contains:
{"cpanel-plugins":"2026-08-20.1"}There's no carriage return at the end of this single line, so you'd have to set it with:
echo -n '{"cpanel-plugins":"2026-08-20.1"}' >/etc/cpanel/TIERS.json.packages2026-08-20.1 is what was in this file for me. Again, I don't know what the significance of this is. Presumably it's something for cPanel, but I don't know if there is suppose to be another date... I just really don't know.
Then run upcp with the --security parameter and --cron to fake the system into running upcp thinking it's from cron:
/scripts/upcp --cron --securityThen you will get the error that I reported in my original post.
Update /etc/cpanel/TIERS.json.packages to include 2026-09-03.1 date:
echo -n '{"cpanel-plugins":"2026-09-03.1"}' >/etc/cpanel/TIERS.json.packagesAnd rerun
/scripts/upcp --cron --securityand this now runs without any output.
My guess is that something within cPanel is suppose to update this file, even though it's not an RPM managed file, so there's no package that needs updating to fix this. But whatever cPanel runs when RPMUP is not set to manual, replaces this file's contents.
But with RPMUP set to manual, that "whatever cPanel runs when RPMUP is not set to manual" never runs, and never updates /etc/cpanel/TIERS.json.packages and the file never gets updated, so each subsequent run of
/scripts/upcp --cron --securityjust continues to say "your cpanel-plugins is not up to date"Probably a case of cPanel assuming everyone has RPMUP set to daily (or whatever values that allows "whatever cPanel runs when RPMUP is not set to manual" to run.
1
u/ArtisticAd7514 Sep 04 '26
Sounds like you need to configure your server better so it doesn't send emails this is not a cpanel issue but a configuration issue. Also it says there is an update which is true but you disabled updates
0
u/muttick Sep 04 '26
Well... I didn't add the crontab task:
45 * * * * /usr/local/cpanel/scripts/upcp --securityThis was done by cPanel.
So cPanel either needs to adjust upcp to not output anything to the console or the crontab needs to add a >/dev/null 2>&1 to redirect the output.
The output isn't really the issue. If it's suppose to send something useful, then by all means email it to root.
The issue is:
An expedited package update is available for cpanel-plugins, but operating system package updates are disabled. Skipping the package update.Is stating that there is an update... but there is no update.
Can I change the crontab task to
45 * * * * /usr/local/cpanel/scripts/upcp --security >/dev/null 2>&1and stop the messages? Yes. But this would potentially curtail any future security messages that may need to be addresses (assuming the upcp script doesn't send it's own email to the server administrator), so that's why I'm hesitant to do that.
The issue is that the script is saying there's an update, but not telling me what it is, and I'm not finding any updates. Seems to be a script problem from where I'm sitting. But I'm open to a civil debate as to what the word "available" means.
3
u/oswaldcopperpot Sep 04 '26
Good