What Happened
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
Why It Matters
Report facts: The article describes a cPanel flaw affecting all supported cPanel/WHM versions, where an authenticated hosting account with mail privileges can use EmailTrack to create arbitrary files on the server and escalate to code execution as root, potentially allowing full control of the server. RealGround analysis: For organizations hosting AI infrastructure or models on cPanel-managed servers, this constitutes a critical AI supply chain risk, as an exploited panel could be used to tamper with AI services, training data, or deployment pipelines. Security teams should treat shared hosting and control panels as part of the AI infrastructure perimeter, review where AI workloads depend on cPanel-based servers, and enforce rapid patching plus isolation of AI assets from vulnerable shared environments. Aligning AI supply chain inventories and SBOMs with privileged access on hosting platforms helps ensure that similar control-plane vulnerabilities cannot be leveraged to compromise AI systems.
RealGround Analysis
This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
