Security: Privilege Escalation via Phusion Passenger's Watchdog API

  • Monday, 17th August, 2026
  • 06:26am
cPanel & WHM Security Advisory
Privilege Escalation via Phusion Passenger's Watchdog API

Sysop Solutions Security Advisory

cPanel has disclosed a security vulnerability affecting Phusion Passenger's Watchdog API, which can potentially allow local privilege escalation on affected servers.

Important: This vulnerability does not affect default cPanel installations. It is only applicable to servers where one or more of the affected Passenger packages have been installed.

Vulnerability Details

Component: Phusion Passenger Watchdog API
Impact: Local Privilege Escalation
Affected Platform: cPanel & WHM servers with affected Passenger packages installed

According to cPanel, all cPanel & WHM versions can be affected if one or more of the vulnerable Passenger packages are installed.

Affected Passenger Packages

The following packages may be affected:

  • ea-apache24-mod-passenger
  • ea-passenger-src
  • ea-ruby27-rubygem-passenger
  • ea-ruby27-mod_passenger
  • ea-ruby24-rubygem-passenger
  • ea-ruby24-mod_passenger
  • ea-nginx-passenger

Patched Versions

Passenger Package Patched Version
ea-apache24-mod-passenger 6.1.8-2
ea-passenger-src 6.1.8-2
ea-ruby27-rubygem-passenger 6.0.27-2 (EL7)
6.1.8-2 (EL8)
ea-ruby27-mod_passenger 6.0.27-2 (EL7)
6.1.8-2 (EL8)
ea-ruby24-rubygem-passenger 6.0.20-4
ea-ruby24-mod_passenger 6.0.20-4
ea-nginx-passenger 6.1.8-2
Recommended Action

If Passenger is installed on your server, we strongly recommend updating the affected packages to their latest available versions.

Update Passenger Packages

cPanel provides the following command to update all installed packages:

/scripts/update-packages

This command updates the installed packages and applies the latest available fixes.

Sysop Solutions Customers

If your server is managed by Sysop Solutions, our team can review the installed Passenger packages and ensure that applicable security updates are applied.

Customers managing their own servers should verify whether Passenger is installed and update the affected packages as soon as possible.

Need Assistance?

If you are unsure whether your server is affected or need assistance updating Passenger, please contact Sysop Solutions Support.

Official cPanel Advisory

For complete technical details, affected packages, patched versions, verification commands, and additional security guidance, please refer to the official cPanel advisory:

View Official cPanel Security Advisory

Sysop Solutions recommends keeping all server software and security packages up to date to help protect your infrastructure.

Regards,
Sysop Solutions
Hosting & Server Management

« Back