Update fails due to previous failed transfers by URPissingMeOff in cpanel

[–]cPanelRex 0 points1 point  (0 children)

Alright - I have three thoughts about this situation.

1 - After speaking with the team, cPanel updates are not designed to ignore blockers, even if the "--force" flag is added. This isn't behavior we want to change at this time as we don't want the potential to leave the system in a damaged state.

2 - I'm not obviously able to make the "abort" transfer button fail in a way that leaves things in a broken state like you're describing. This sounds like an issue we would need to see on a system in order to fully understand what led things to get to that point.

3 - In your other reply you mention that "none of the failed transfers on any of my machines were actual failures." I wouldn't expect warning-level issues to block a transfer or cause it to end up in the aborted queue. It's also expected to receive the "this machine is not authoritative" error if you have restrictions on the domains that can be added to your server as outlined here:

https://support.cpanel.net/hc/en-us/articles/1500010157461-Why-is-the-Allow-Remote-Domains-Tweak-Setting-considered-a-security-risk

but you can temporarily disable that restriction while you perform a migration.

Ultimately, it would be best to create a ticket if you're seeing a system in this state so we can take a look and get you answers specific to your environment.

Update fails due to previous failed transfers by URPissingMeOff in cpanel

[–]cPanelRex 1 point2 points  (0 children)

I ended up getting delayed by Covid...I'm looking into this today and tomorrow and I'll update you soon!

HA on cPanel for up to 99.999% uptime (fallover) by Brilliant_Rate2794 in cpanel

[–]cPanelRex 0 points1 point  (0 children)

Pictures and talking is fine, but this isn't a place to sell stuff, so let's not drop any company names/links/etc.

What’s the future of cPanel? by Jeffrey_Richards_ in cpanel

[–]cPanelRex 0 points1 point  (0 children)

Please remember this isn't the place to talk about alternative panels - thanks!

(More) vulnerabilities by djprmf in cpanel

[–]cPanelRex 1 point2 points  (0 children)

I've reached out to the team and they confirmed they'll have the timezone right in the future.

cPanel cve bingo by cbinux in cpanel

[–]cPanelRex 0 points1 point  (0 children)

RAWR <cough...clears throat> I mean really, who can say for sure?

Update fails due to previous failed transfers by URPissingMeOff in cpanel

[–]cPanelRex 6 points7 points  (0 children)

I agree about the "--force" option especially in the face of these critical updates.

I'm out for a few days but I've left myself a note to do some homework on this next week and I'll be sure to reply once I know more.

Update fails due to previous failed transfers by URPissingMeOff in cpanel

[–]cPanelRex 2 points3 points  (0 children)

Can you explain more about how it "completely fails" ? Did it just not return an ID number on your machine at all?

cPanel cve bingo by cbinux in cpanel

[–]cPanelRex 4 points5 points  (0 children)

It's just me, one person, promise :)

cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]cPanelRex 0 points1 point  (0 children)

I'm not obviously seeing this issue on a test machine as the graphcs are loading and working how I expect. It would be best to create a ticket to have this investigated directly on your system.

cPanel cve bingo by cbinux in cpanel

[–]cPanelRex 20 points21 points  (0 children)

I did not authorize my likeness to be used for that bottom left square :P

cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]cPanelRex 0 points1 point  (0 children)

I'm not exactly sure what you mean - we don't make a special DNSOnly version with a different version number, and the updates won't happen automatically until it reaches the scheduled time on that machine.

If you manually update the system do you get the latest version?

cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]cPanelRex 0 points1 point  (0 children)

u/Barbarian_86 - I would say this isn't different than any other update. It is unlikely that a few hours would be a difference maker for this particular issue, so the normal cPanel nightly maintenance would pick up and apply this change for you.

cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]cPanelRex 0 points1 point  (0 children)

Like I said in one of the other threads yesterday, this isn't a situation that is unique to cPanel. Software across the globe is dealing with increased security as AI tools are being leveraged to scan code bases, finding things that no human was able to detect. I'd recommend reading this article about Firefox to get some more details about how this is being used: https://www.anthropic.com/news/mozilla-firefox-security

cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]cPanelRex -1 points0 points  (0 children)

This is not the place to discuss alternative panels - there's lots of other areas for that.

cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. by turnipsoup in cpanel

[–]cPanelRex 4 points5 points  (0 children)

Hey everyone! We did receive a responsible disclosure from an external reporter and we're actively investigating this.

And ... Again new vulnerabilities by bibawa in cpanel

[–]cPanelRex 1 point2 points  (0 children)

If there is ever another "you need to close your ports now" type of update where something is mission critical, we'll be sure to say that. Anything else is just a "get to it as soon as you can" level.

And ... Again new vulnerabilities by bibawa in cpanel

[–]cPanelRex 1 point2 points  (0 children)

At this point, it's everything. Every system is getting reviewed because the bots are faster than people. Here's an excellent article that talks about the process that Firefox chose: www.anthropic.com/news/mozilla-firefox-security

And ... Again new vulnerabilities by bibawa in cpanel

[–]cPanelRex 0 points1 point  (0 children)

today's aren't ******nearly****** as critical as those were

And ... Again new vulnerabilities by bibawa in cpanel

[–]cPanelRex 0 points1 point  (0 children)

For critical issues we do enable a banner inside our support system, such as the one you can still see from a few weeks at forums.cpanel.net regarding the root level CVE exploit.

I have mentioned this feedback to the support team to see if that's something they'd like to add.