Critical cPanel Flaw Could Let a Hosting Customer Take Root Control of a Whole Server

cPanel published a security advisory on August 27, 2026, disclosing a critical vulnerability in the domain-parking and addon-domain functionality of cPanel & WHM. Tracked as CVE-2026-65643, the flaw allows an authenticated account holder with permission to add parked or addon domains to create arbitrary files on the server, which can ultimately be abused to achieve code execution as the root user.

According to cPanel’s own advisory, successful exploitation “leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.” The vulnerability affects all currently supported versions of cPanel & WHM. Patched versions are 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP2 build 11.138.1.7 or later; servers running end-of-life cPanel releases must first upgrade to a supported version before they can receive the fix.

Particularly Severe for Shared and Multi-Tenant Hosting

Security researchers covering the disclosure noted that the flaw’s impact is amplified in shared-hosting environments, where a single low-privilege tenant account with domain-management permissions could serve as a stepping stone to compromising every other customer hosted on the same server — including the ability to deploy persistent backdoors, alter website content, exfiltrate databases, and manipulate server configuration across multiple unrelated hosted accounts.

cPanel has not disclosed evidence of active exploitation, and as of the August 27, 2026 update to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, CVE-2026-65643 was not listed. The advisory also carries no published CVSS score; as of August 28, 2026, the CVE Program’s own record store had not yet published a formal record for the vulnerability, even though two unrelated cPanel plugin flaws disclosed on July 31 already had entries at the time of the check.

Given how widely cPanel is deployed across web and hosting infrastructure, administrators are advised to prioritize the update, particularly on multi-tenant servers where the domain-parking feature is exposed to lower-trust account holders.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *