cPanel Directory Traversal Vulnerability in Team Manager API Allows Privilege Escalation

Vulnerability

A directory traversal vulnerability has been identified in cPanel versions 110 through 132, within the Team Manager API. This vulnerability allows for the overwriting of arbitrary files, which could lead to unauthorized privilege escalation to the root user.

Impact

Exploitation of this vulnerability could result in unauthorized access to root privileges.

Remediation

Users can upgrade to cPanel & WHM version 132 or later, where this vulnerability has been fixed.

Added: Dec 11, 2025, 9:22 PM
Updated: Dec 11, 2025, 9:22 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
10.0
exploitability
5.4
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.