An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server…lead[ing] to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.
This has a severe impact for multi-tenant hosting exposing:
Private website files and source code
Customer databases and sensitive records
Private email accounts and communications
System configuration files and credentials
Server-wide backups and logs
Affected Versions
This vulnerability affects all supported versions of cpanel and WHM. These are the patched builds you should update to using the upcp script or the WHM interface:
11.110.0.141 or later
11.134.0.53 or later
11.136.0.37 or later
11.138.0.2 or later
WP2: 11.138.1.7 or later
Actions
If you can’t update, stop users from adding new parked or addon domains.
As far as I know there is no confirmation of exploitation. However, I am aware of two separate incidents where the compromise of an account in a shared hosting environment (which was based on cPanel) ultimately lead to full takeover of the affected host systems. The incidents were especially interesting because it wasn’t entirely clear how the move from compromised user account to full takeover happened - but everything in those incidents would, at least roughly, fit for this issue.
Again, I can’t confirm it definitely, but I would treat this as ‘actively exploited’, just to be on the safe side.