Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

ZPanel Privilege Escalation Vulnerability via Misconfigured zsudo

Vulnerability

A local privilege escalation vulnerability exists in ZPanel due to a helper binary called zsudo, which is intended for restricted privilege escalation for administrative tasks. When zsudo is misconfigured in the sudoers file, low-privileged users can exploit it to execute arbitrary commands as root. This vulnerability allows local attackers with shell access to escalate privileges by writing a payload to a directory they can write to and executing it using zsudo. The issue is particularly significant in post-exploitation scenarios after a web server compromise, where the attacker gains access to zsudo.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling a user to execute commands with root privileges.

Reproduction

To reproduce this vulnerability, a user must have shell access and be in a ZPanel environment where zsudo is included in the sudoers file. Once these conditions are met, the user can write a payload to a writable directory and execute it using zsudo, thereby escalating privileges to root.

Added: Aug 4, 2025, 6:29 PM
Updated: Aug 4, 2025, 6:29 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
7.5
exploitability
5.7
remediation
8.3
relevance
0.3
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.