Critical cPanel Flaw

Overview

cPanel has released patches for a critical vulnerability in its domain parking and addon domain functionality that could allow authenticated hosting customers to execute code as the root user. Tracked as CVE‑2026‑65643, the flaw impacts all supported versions of cPanel & WHM, making it one of the most severe risks to shared hosting environments in recent years.

Vulnerability Details

  • CVE‑2026‑65643: Authenticated users with permission to add parked or addon domains can create arbitrary files on the server.
  • Impact: Successful exploitation leads to root‑level code execution, giving attackers full control of the server.
  • Scope: All supported versions of cPanel & WHM are affected.

Patched Versions

cPanel has released fixes in the following builds:

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • 11.138.1.7 or later (WP Squared)

Servers configured for automatic daily updates will receive the patched build automatically. Administrators can also manually apply the patch by running:

Code

/scripts/upcp --force

or by upgrading via WHM under Home > cPanel > Upgrade to Latest Version.

Exploitation Status

  • No evidence of exploitation has been reported yet.
  • The flaw is not listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog as of August 27, 2026.
  • However, past cPanel flaws (e.g., CVE‑2026‑41940) have been weaponized in ransomware campaigns, underscoring the urgency of patching.

Defensive Guidance

Administrators should:

  • Update immediately to the latest supported builds.
  • Verify installed build under Server Configuration > Update Preferences.
  • Restrict domain permissions: Limit addon/parked domain privileges to trusted accounts.
  • Monitor logs: Investigate suspicious activity in Apache error logs and server logs.
  • Upgrade end‑of‑life versions: Unsupported builds will not receive patches.

Expert in the Cloud Insight

This flaw highlights the high‑risk nature of shared hosting environments, where one customer’s account can potentially compromise an entire server. With root execution at stake, patching is not optional — it is survival. Hosting providers must enforce rapid patch cycles, strict account permissions, and proactive monitoring to prevent privilege escalation attacks from spreading across multi‑tenant infrastructure.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.