Back to Security Advisories

EasyApache 4 25.79

Security and maintenance updates We released updated packages for EasyApache 4. This security release hardens the Phusion Passenger agent API authorization boundary so an empty API account database confers no privileges, resolving a local privilege escalation in the Passenger Watchdog API (SEC-75753). The fix is app…

Critical
cPanel

Affected Versions

25.79

2026 August 13

Security and maintenance updates

We released updated packages for EasyApache 4.

This security release hardens the Phusion Passenger agent API authorization boundary so an empty API account database confers no privileges, resolving a local privilege escalation in the Passenger Watchdog API (SEC-75753). The fix is applied to ea-passenger-src, ea-ruby27-passenger, ea-apache24-mod-passenger, and ea-nginx-passenger.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System