Security Flaw in cPanel and WHM Allowed 2FA Bypasses

security flaw in cpanel could have led to 2fa bypass attacks

Security researchers just reported that cPanel, perhaps the most common provider of admin tools for web hosting, is vulnerable. Security flaws resided in cPanel and WebHost Manager (WHM) web hosting platform, enabling remote hackers with valid credentials to bypass two-factor authentication (2FA) on targeted accounts.

How to Fix cPanel Security Flaws?

In case you are having problems with cPanel security, we would strongly recommend that you implement a complete website fix immediately. The most professional solution is using Fixed.net to conduct a complete website repair, that includes:

  1. Quick malware removal.
  2. Errors and redirects fix.
  3. Complete site repair.
  4. White screen of death fix.
  5. Contact forms error fix.
  6. eCommerce checkout errors repair.
  7. Active maintenance and backup + prevention.

More About The Issues in cPanel And WHM

Digital Defense researchers discovered and reported one of the issues, which is now known as SEC-575. The good news is that the flaw is addressed in versions 11.92.0.2, 11.90.0.17, and 11.86.0.32 of cPanel.

As explained by Digital Defense researchers, cPanel &WHM version 11.90.0.5 (90.0 Build 5) contain a two-factor authentication bypass flaw.

The issue could be used in brute force attacks, “resulting in a scenario where an attacker with knowledge of or access to valid credentials could bypass two-factor authentication protections on an account.” Testing carried out by the team showed that an attack “can be accomplished in minutes.”

The other issues are tracked as SEC-577 (Self-XSS vulnerability in WHM Transfer Tool interface) and SEC-567 (URL parameter injection vulnerabilities in multiple interfaces). You can learn more about them from the official advisory.

cPanel and WHM (Web Host Manager) provides a Linux-based control panel for web admins to control site and server management.

Management tasks that can be performed with the software include adding sub-domains and system and control panel maintenance. Currently, more than 70 million domains operate via cPanel’s software.

According to cPanel’s official advisory, the SEC-575 issue stemmed from the lack of prevention of repeatedly submitting 2FA codes.

This condition enabled hackers to circumvent 2FA checks via brute force techniques.

“Failed validation of the two-factor authentication code is now treated as equivalent to a failure of the account’s primary password validation and rate limited by cPHulk,” the software provider added.

Thе 2FA vulnerability was discovered by Michael Clark and Wes Wright of Digital Defense.

To avoid any attacks against your website, you should keep track of any pending updates of all the software you utilize.

Researched and created by:
Krum Popov
Passionate web entrepreneur, has been crafting web projects since 2007. In 2020, he founded HTH.Guide — a visionary platform dedicated to streamlining the search for the perfect web hosting solution. Read more...
Technically reviewed by:
Metodi Ivanov
Seasoned web development expert with 8+ years of experience, including specialized knowledge in hosting environments. His expertise guarantees that the content meets the highest standards in accuracy and aligns seamlessly with hosting technologies. Read more...

Leave a Comment

Your email address will not be published. Required fields are marked *

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree
At HTH.Guide, we offer transparent web hosting reviews, ensuring independence from external influences. Our evaluations are unbiased as we apply strict and consistent standards to all reviews.
While we may earn affiliate commissions from some of the companies featured, these commissions do not compromise the integrity of our reviews or influence our rankings.
The affiliate earnings contribute to covering account acquisition, testing expenses, maintenance, and development of our website and internal systems.
Trust HTH.Guide for reliable hosting insights and sincerity.