cPanel Security: Privilege Escalation via Phusion Passenger's Watchdog API

Incident Report for InterServer

Investigating

Phusion Passenger Watchdog API privilege escalation vulnerability:
https://support.cpanel.net/hc/en-us/articles/42694659893143-Security-Privilege-Escalation-via-Phusion-Passenger-s-Watchdog-API?utm_medium=email&_hsmi=433242580&utm_content=433242580&utm_source=hs_email

cPanel has released patches for the above root exploit, however cloudlinux the os vendor in use has not. Out of caution the package will be removed on systems until a patch is released.
Posted Aug 14, 2026 - 11:04 EDT
This incident affects: Services (Webhosting).