Critical cPanel Vulnerability (CVE-2026-65643) Grants Root Access via Low-Privilege Accounts
A severe vulnerability in cPanel and WHM, the widely used web hosting control panel software, has been disclosed, allowing authenticated users with low privileges to gain root-level control of entire servers. Tracked as CVE-2026-65643, the flaw was detailed in an advisory published on August 27, 2026, by cPanel support engineer Devon Courtney.
The vulnerability resides in cPanel’s domain parking functionality, a common feature enabling users to point additional domains to an existing website. Exploitation requires only a legitimate cPanel account with permission to add parked or addon domains, making it accessible to attackers via cheap shared hosting plans or compromised accounts. The flaw allows arbitrary file creation anywhere on the server, leading to remote code execution (RCE) as root effectively granting full control over the system.
On shared hosting environments, this poses a catastrophic risk: a single compromised account could expose all websites, databases, and email accounts on the same server. Hosting providers face the threat of mass defacement, data theft, malware deployment, or lateral movement across their infrastructure.
The vulnerability affects all supported cPanel and WHM versions, with patches released for:
- 11.110.0.141 or later
- 11.134.0.53 or later
- 11.136.0.37 or later
- 11.138.0.2 or later
- WP2 build 11.138.1.7 or later
Servers running end-of-life (EOL) versions remain unpatched unless upgraded to a supported release. While cPanel typically deploys automatic updates, administrators with manual policies must verify their build numbers and apply fixes immediately. Hosting providers are also advised to review and restrict domain-parking permissions on unpatched servers to mitigate risk.
Given cPanel’s dominance in shared and reseller hosting, rapid exploitation attempts are expected, making urgent patching the primary defense.
Source: https://cybersecuritynews.com/critical-cpanel-vulnerability/
cPanel TPRM report: https://www.rankiteo.com/company/cpanel
"id": "cpa1787891604",
"linkid": "cpanel",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'All users of affected '
'cPanel/WHM versions',
'industry': 'Web Hosting, IT Infrastructure',
'name': 'cPanel and WHM',
'type': 'Web hosting control panel software'}],
'attack_vector': 'Authenticated low-privilege account access',
'data_breach': {'sensitivity_of_data': 'High (potential for personally '
'identifiable information, payment '
'data, etc.)',
'type_of_data_compromised': ['Websites',
'Databases',
'Email accounts']},
'date_publicly_disclosed': '2026-08-27',
'description': 'A severe vulnerability in cPanel and WHM allows authenticated '
'users with low privileges to gain root-level control of '
'entire servers. The flaw, tracked as CVE-2026-65643, resides '
'in cPanel’s domain parking functionality and enables '
'arbitrary file creation leading to remote code execution '
'(RCE) as root. Exploitation requires only a legitimate cPanel '
'account with permission to add parked or addon domains, '
'posing a catastrophic risk in shared hosting environments.',
'impact': {'data_compromised': 'All websites, databases, and email accounts '
'on the same server',
'operational_impact': 'Mass defacement, data theft, malware '
'deployment, lateral movement across '
'infrastructure',
'systems_affected': 'cPanel and WHM servers'},
'post_incident_analysis': {'corrective_actions': 'Patching, permission '
'restrictions, and upgrading '
'EOL versions',
'root_causes': 'Vulnerability in cPanel’s domain '
'parking functionality allowing '
'arbitrary file creation and RCE as '
'root'},
'recommendations': 'Apply patches immediately, review and restrict '
'domain-parking permissions on unpatched servers, upgrade '
'EOL versions to supported releases, and monitor for '
'exploitation attempts.',
'references': [{'source': 'cPanel Advisory'}],
'response': {'communication_strategy': 'Advisory published by cPanel support '
'engineer Devon Courtney',
'containment_measures': 'Patches released for affected versions; '
'administrators advised to verify build '
'numbers and apply fixes immediately',
'remediation_measures': 'Upgrade to patched versions '
'(11.110.0.141+, 11.134.0.53+, '
'11.136.0.37+, 11.138.0.2+, WP2 build '
'11.138.1.7+)'},
'title': 'Critical cPanel Vulnerability (CVE-2026-65643) Grants Root Access '
'via Low-Privilege Accounts',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-65643 (cPanel domain parking '
'functionality)'}