In Progress Username allowed in password

Operating System & Version
CENTOS 7.8
cPanel & WHM Version
v86.0.21

Sis.temas

Registered
May 19, 2020
2
0
1
Spain
cPanel Access Level
DataCenter Provider
I have recently verified that you can use your own username as a password (at least for email from CPanel)

Example:
Email: [email protected]
Password: john.smith23

My CPanel says it is a very secure password!!

Is there a way to prevent this terrible feature?
 

Sis.temas

Registered
May 19, 2020
2
0
1
Spain
cPanel Access Level
DataCenter Provider
That wouldn't help much because the password "john.smith23", which is exactly the username, has already a score of 94.
There should be a specific check that the username is not contained in the password.

After reading this I would think that this option would exist:
But my experience is just the opposite of what that thread says. I'm quite confused.
 

cPanelLauren

Forums Analyst II
Staff member
Nov 14, 2017
11,214
1,006
313
Houston
That Feature request you note is referencing the cPanel account's username you're referencing an email account - which I'd assume would be different. I do agree with you that this should not be the case. I was able to replicate this and I will open a case on this and update you of the case ID as soon as I have it available.