Control Web Panel
WebPanel => CentOS-WebPanel Bugs => Topic started by: simonjwoolf on October 07, 2026, 08:42:58 AM
-
Since the CWP update to 1.18 my user panels are completely broken. I see a message in the admin that I should stop and start the firewall. This did not make any difference.
The links from the admin panel all produce 404 errors, and if I try to manually login then I get a 500 error. I took a log in the apache logs but cannot find anywhere where the hostname access is logged.
I don't know if this is a reoccurrence of the problem described here: https://forum.centos-webpanel.com/centos-webpanel-bugs/fix-user-panel-login-is-not-working/, or something new?
-
CWP stores access and error logs of the panel in:
/usr/local/cwpsrv/logs/
/usr/local/cwp/php71/var/log
-
Many thanks. This reveals a whole stack of unexpected errors. I'm lost!
2026/10/07 10:53:33 [error] 1932162#0: *1902 FastCGI sent in stderr: "PHP message: PHP Warning: main(): open_basedir restriction in effect. File(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php) is not within the allowed path(s): (/home/username:/tmp:/usr/local/cwpsrv/var/services/users:/usr/local/cwpsrv/var/services/twig/:) in /usr/local/cwpsrv/var/services/users/index.php on line 0
PHP message: PHP Warning: main(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php): failed to open stream: Operation not permitted in /usr/local/cwpsrv/var/services/users/index.php on line 0
PHP message: PHP Warning: main(): open_basedir restriction in effect. File(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/classes/CWPAuth.php) is not within the allowed path(s): (/home/username:/tmp:/usr/local/cwpsrv/var/services/users:/usr/local/cwpsrv/var/services/twig/:) in /usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php on line 0
PHP message: PHP Warning: main(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/classes/CWPAuth.php): failed to open stream: Operation not permitted in /usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php on line 0
PHP message: PHP Fatal error: main(): Failed opening required '/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/classes/CWPAuth.php' (include_path='.:/usr/local/cwp/php71/lib/php') in /usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php on line 0" while reading response header from upstream, client: 80.113.2.130, server: localhost, request: "POST /username/ HTTP/1.1", upstream: "fastcgi://unix:/usr/local/cwp/php71/var/sockets/username.sock:", host: "hostname.com:2083", referrer: "https://hostname.com:2031/"
(I replaced my server hostname and the user in question with generic text above)
-
According to the error, PHP open_basedir blocks access to the files of the panel:
What kind of URL do you use to access the panel ? Is it something like:
https://cpanel.domain.com ?
If so, try:
https://domain.com:2031/
Did you change PHP settings recently ?
-
Can confirm user panel logs in fine on version 1.18
-
No I didn't change any PHP settings. And I can't access the panels via either URL format.
I did deal with a similar hacking exploit to the one you described, I wonder if I accidentally locked something down.
-
Did you try disabling mod_secutity?
-
1. Open the file:
/usr/local/cwpsrv/conf.d/users.conf
and check all lines that contains "open_basedir ...".
Make sure the open_basedir is configured at listed below:
fastcgi_param PHP_ADMIN_VALUE "open_basedir = /tmp/:/usr/local/cwpsrv/var/services/users/login/:/usr/local/cwpsrv/var/services/users/cwp_theme/:/usr/local/cwpsrv/var/services/twig/";
You should see 4 absolutely identical lines there.
Make backup and fix the lines if they have different values.
2. Open the file:
/usr/local/cwpsrv/conf.d/users/USERNAME.conf
(USERNAME is the username of some regular (not root) problematic account)
Check the line with open_basedir there. It should be:
fastcgi_param PHP_ADMIN_VALUE "open_basedir =/home/USERNAME:/home/jail/USERNAME/./home/USERNAME:/tmp:/var/softtmp:/usr/local/cwpsrv/var/services/users:/usr/local/cwpsrv/var/services/user_files/modules:/usr/local/cwpsrv/var/services/twig:";
!!! Make backup of the file before any modifications and fix values.
3. Restart cwp if you modified some files:
service cwp-phpfpm restart
service cwpsrv restart
service cwpsrv-phpfpm restart