Author Topic: User cpanel URLs and login completely broken since CWP 1.18 update  (Read 503 times)

0 Members and 1 Guest are viewing this topic.

Offline
*
Since the CWP update to 1.18 my user panels are completely broken. I see a message in the admin that I should stop and start the firewall. This did not make any difference.

The links from the admin panel all produce 404 errors, and if I try to manually login then I get a 500 error. I took a log in the apache logs but cannot find anywhere where the hostname access is logged.

I don't know if this is a reoccurrence of the problem described here: https://forum.centos-webpanel.com/centos-webpanel-bugs/fix-user-panel-login-is-not-working/, or something new?

Offline
****
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #1 on: October 07, 2026, 08:47:44 AM »
CWP stores access and error logs of the panel in:

/usr/local/cwpsrv/logs/
/usr/local/cwp/php71/var/log

Offline
*
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #2 on: October 07, 2026, 08:58:38 AM »
Many thanks. This reveals a whole stack of unexpected errors. I'm lost!

Code: [Select]
2026/10/07 10:53:33 [error] 1932162#0: *1902 FastCGI sent in stderr: "PHP message: PHP Warning:  main(): open_basedir restriction in effect. File(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php) is not within the allowed path(s): (/home/username:/tmp:/usr/local/cwpsrv/var/services/users:/usr/local/cwpsrv/var/services/twig/:) in /usr/local/cwpsrv/var/services/users/index.php on line 0
PHP message: PHP Warning:  main(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php): failed to open stream: Operation not permitted in /usr/local/cwpsrv/var/services/users/index.php on line 0
PHP message: PHP Warning:  main(): open_basedir restriction in effect. File(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/classes/CWPAuth.php) is not within the allowed path(s): (/home/username:/tmp:/usr/local/cwpsrv/var/services/users:/usr/local/cwpsrv/var/services/twig/:) in /usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php on line 0
PHP message: PHP Warning:  main(/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/classes/CWPAuth.php): failed to open stream: Operation not permitted in /usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php on line 0
PHP message: PHP Fatal error:  main(): Failed opening required '/usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/classes/CWPAuth.php' (include_path='.:/usr/local/cwp/php71/lib/php') in /usr/local/cwpsrv/var/services/user_files/modules/cwp_framework/CWPUserIndex.php on line 0" while reading response header from upstream, client: 80.113.2.130, server: localhost, request: "POST /username/ HTTP/1.1", upstream: "fastcgi://unix:/usr/local/cwp/php71/var/sockets/username.sock:", host: "hostname.com:2083", referrer: "https://hostname.com:2031/"

(I replaced my server hostname and the user in question with generic text above)

Offline
****
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #3 on: October 07, 2026, 09:51:39 AM »
According to the error, PHP open_basedir blocks access to the files of the panel:

What kind of URL do you use to access the panel ? Is it something like:
https://cpanel.domain.com ?

If so, try:
https://domain.com:2031/

Did you change PHP settings recently ?

Offline
**
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #4 on: October 07, 2026, 10:01:08 AM »
Can confirm user panel logs in fine on version 1.18

Offline
*
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #5 on: October 07, 2026, 10:05:58 AM »
No I didn't change any PHP settings. And I can't access the panels via either URL format.

I did deal with a similar hacking exploit to the one you described, I wonder if I accidentally locked something down.

Offline
*
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #6 on: October 07, 2026, 10:50:56 AM »
Did you try disabling mod_secutity?

Offline
****
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #7 on: October 07, 2026, 10:56:37 AM »
1. Open the file:

/usr/local/cwpsrv/conf.d/users.conf

and check all lines that contains "open_basedir ...".

Make sure the open_basedir is configured at listed below:

Code: [Select]
fastcgi_param   PHP_ADMIN_VALUE "open_basedir = /tmp/:/usr/local/cwpsrv/var/services/users/login/:/usr/local/cwpsrv/var/services/users/cwp_theme/:/usr/local/cwpsrv/var/services/twig/";

You should see 4 absolutely identical lines there.

Make backup and fix the lines if they have different values.


2. Open the file:
/usr/local/cwpsrv/conf.d/users/USERNAME.conf
(USERNAME is the username of some regular (not root) problematic account)

Check the line with open_basedir there. It should be:

Code: [Select]
fastcgi_param   PHP_ADMIN_VALUE "open_basedir =/home/USERNAME:/home/jail/USERNAME/./home/USERNAME:/tmp:/var/softtmp:/usr/local/cwpsrv/var/services/users:/usr/local/cwpsrv/var/services/user_files/modules:/usr/local/cwpsrv/var/services/twig:";


!!! Make backup of the file before any modifications and fix values.

3. Restart cwp if you modified some files:

Code: [Select]
service cwp-phpfpm restart
service cwpsrv restart
service cwpsrv-phpfpm restart

Offline
*
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #8 on: October 09, 2026, 03:35:12 PM »
Many thanks. I checked this and the value in /usr/local/cwpsrv/conf.d/users/USERNAME.conf was vary marginally different (identical to the values in /usr/local/cwpsrv/conf.d/users.conf) but correcting it as per your suggestion has not solved the problem.

Also, I don't know if it is significant, but the directory /usr/local/cwpsrv/conf.d/users/ was empty apart from the one user I had used to test the login (I have 12 clients hosted on the server)

I am seeing multiple issues as follows:

 1. When trying to auto-login to a user's control from the admin panel, I get 404 errors on the format https://server.name:2083/username (forwarded from the cp link https://server.name:2083/token=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx)

 2. If I go to the URL  https://server.name:2083/ and enter a username and password, I get the "succesfully logged in" message briefly, then the browser forwards me back to the login page

This is the same for all user accounts on the server.

I am wondering if I should run the apache vhost rebuild script as suggested in the older thread about this problem.

Any thoughts?
« Last Edit: October 09, 2026, 03:37:27 PM by simonjwoolf »

Offline
*****
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #9 on: October 09, 2026, 03:46:27 PM »
CWP 1.18 Admin (:2031) and User (:2083) interfaces are working fine on AL9.

What OS are you running?

Offline
****
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #10 on: October 09, 2026, 10:10:57 PM »
The folder:
 /usr/local/cwpsrv/conf.d/users/
contains identical config files with minor changes for each user.

Just generate other config fiels for other users using the config file of the test user.

Additionally, make sure the folder:
/usr/local/cwpsrv/var/services/users
contains symlinks to /usr/local/cwpsrv/var/services/users for each user:


Offline
*
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #11 on: October 10, 2026, 01:07:35 PM »
I am running AL 8.10

Offline
*
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #12 on: October 10, 2026, 03:15:19 PM »
I finally got to the bottom of this.

While I was troubleshooting the OMRIG exploit as described here https://forum.centos-webpanel.com/centos-webpanel-bugs/possible-cwp-security-issue-root-compromise-omrig-miner-and-port-2304-exposed/, I found that root's home directory contains a mysql config file with a plaintext root password (~/.my.cnf)

Concerned that the hacker might be accessing databases using this information, I commented out the correct password and added a spurious one.

It seems that CWPro requires this plaintext password and uses it when processing user control panel logins. Even worse - when login fails, the plaintext password appears in the CWPSRV logs! (/usr/local/cwpsrv/logs/error_log)

Restoring the .my.cnf to its original state enabled my user control panels again.

But there is no explanation as to why all the username.conf files disappeared from the folder /usr/local/cwpsrv/conf.d/users

I have had to manually recreate them as per your suggestion. But this alone is also not enough. The socket files for the users are missing. They only get recreated when the user logs in normally - not via the auto-login from the admin control panel.

Offline
****
Re: User cpanel URLs and login completely broken since CWP 1.18 update
« Reply #13 on: October 10, 2026, 09:48:35 PM »
Set the permissions on the ~/.my.cnf file to 640 or 600 to prevent other users from accessing it. The file must be owned by root:root.

Additionally, check the permissions of the /root directory. It must also be owned by root:root, with permissions set to 750 or 550 (no permissions for others).

I suspect that the user files may have been removed by the CWP update process. I'm not sure exactly what CWP does during the upgrade process. However, it may execute some SQL queries, and if some SQL query fails due to incorrect login credentials, this could lead to unexpected behavior during the upgrade. Just a guess.