Some security researchers discovered a major security flaw in cPanel, a popular software suite used by web hosting companies to manage their clients' websites.
The bug, discovered by the security researchers at Digital Defense, allows attackers to bypass two-factor authentication (2FA) on cPanel accounts.
These accounts are used by website owners to access and manage their websites and the underlying server settings . Access to these accounts is critical, as once compromised, they give threat actors complete control over a victim's website .

On its website, cPanel boasts that its software is currently used by hundreds of web hosting companies to manage more than 70 million domains worldwide.
But in a press release today, Digital Defense says that 2FA in older cPanel & WebHost Manager (WHM) software was vulnerable to brute-force attacks that allowed threat actors to guess URL parameters and bypass 2FA – if 2FA was enabled on an account.
While brute-forcing attacks, in general, usually take hours or days to execute, in this particular case, the attack was executed in just a few minutes, Digital Defense said today.
Also, exploiting this bug requires attackers to have valid credentials of a targeted account.
While this may make some website owners think that the error is not significant, it is actually the opposite, as 2FA solutions were invented to protect against phishing attacks and, as a result, any 2FA bypass such as this error should be treated with the utmost caution.
The good news is that Digital Defense privately reported the bug – which was named SEC-575. Also, the cPanel team released some patches last week.
Website owners who use 2FA when logging into cPanel can see if their web hosting provider has released the update to their cPanel installation by checking the platform.
According to the cPanel security advisory, the 2FA bypass issue has been fixed in the cPanel & WHM software versions 11.92.0.2, 11.90.0.17, and 11.86.0.32.
Users should not disable 2FA for their cPanel accounts due to this error, but instead should ask their web hosting providers to update their cPanel installation to the latest version.
