Security: Privilege Escalation via Phusion Passenger's Watchdog API

Incident Report for CloudLinux

Resolved

This incident has been resolved.
Posted Sep 01, 2026 - 23:56 UTC

Update

The fix for alt-mod-passenger is now available in the stable release.
Posted Aug 19, 2026 - 09:41 UTC

Update

alt-mod-passenger is now available in beta:
Name : alt-mod-passenger
Version : 6.0.26
Release : 9.el9.cloudlinux
Architecture : x86_64
Size : 28 M
Source : alt-mod-passenger-6.0.26-9.el9.cloudlinux.src.rpm
Repository : cloudlinux-updates-testing
Summary : Phusion Passenger apache2 module
URL : http://www.cloudlinux.com
License : CloudLinux Commercial License
Description : Phusion Passenger module for Apache

ea-apache24-mod-passenger - cl-ea4 stable
Name : ea-apache24-mod-passenger
Epoch : 1
Version : 6.1.8
Release : 2.el9.cloudlinux
Architecture : x86_64
Size : 12 M
Source : ea-apache24-mod-passenger-6.1.8-2.el9.cloudlinux.src.rpm
Repository : @System
From repo : cl-ea4
Summary : Phusion Passenger application server
URL : https://www.phusionpassenger.com
License : Boost and BSD and BSD with advertising and MIT and zlib
Description : Phusion Passenger(r) is a web server and application server, designed to be fast,
: robust and lightweight. It takes a lot of complexity out of deploying web apps,
: adds powerful enterprise-grade features that are useful in production,
: and makes administration much easier and less complex. It supports Ruby,
: Python, Node.js and Meteor.

ea-ruby27-mod_passenger - cl-ea4 stable
Name : ea-ruby27-mod_passenger
Epoch : 1
Version : 6.1.8
Release : 2.el8.cloudlinux
Architecture : x86_64
Size : 46 M
Source : ea-ruby27-rubygem-passenger-6.1.8-2.el8.cloudlinux.src.rpm
Repository : @System
From repo : cl-ea4
Summary : Apache Module for Phusion Passenger
URL : https://www.phusionpassenger.com
License : Boost and BSD and BSD with advertising and MIT and zlib
Description : This package contains the pluggable Apache server module for Phusion Passenger(r).
Posted Aug 17, 2026 - 19:10 UTC

Monitoring

The patched versions are already available in our stable repository.
Posted Aug 15, 2026 - 04:04 UTC

Investigating

Phusion Passenger Watchdog API privilege escalation vulnerability:
https://support.cpanel.net/hc/en-us/articles/42694659893143-Security-Privilege-Escalation-via-Phusion-Passenger-s-Watchdog-API?utm_medium=email&_hsmi=433242580&utm_content=433242580&utm_source=hs_email

CloudLinux engineering is preparing and testing patched packages. Updated packages will be released shortly.
Posted Aug 14, 2026 - 13:53 UTC
This incident affected: CloudLinux OS Components (EasyApache4 PHP packages).