Critical cPanel Flaw Could Expose Server Root Access


A critical cPanel vulnerability lets certain authenticated users create arbitrary files and potentially execute code with root privileges.

cPanel has released security updates for a critical vulnerability in cPanel & WHM that could allow an authenticated hosting account to gain root-level control of an entire server.

Tracked as CVE-2026-65643, the vulnerability affects the domain parking and addon domain functionality. According to cPanel, an authenticated user with permission to add parked or addon domains could abuse the flaw to create arbitrary files on the server.

The impact can be severe. Successful exploitation can result in code execution under the root account, potentially giving an attacker complete control over the affected server.

cPanel has issued patched builds for its supported branches. The fixed versions listed in the security notification are:

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • 11.138.1.7 or later for WP Squared

The notification specifically includes WP Squared and does not list DNSOnly.

Administrators running servers configured for automatic daily updates should receive the patched build automatically. Those who want to apply the update immediately can log in as root and run /scripts/upcp --force.

The update can also be installed through WHM by going to Home > cPanel > Upgrade to Latest Version. Administrators can then check the installed build through Server Configuration > Update Preferences.

Servers running an end-of-life cPanel version must first move to a supported release in order to receive the security fix.

At the time of the report, cPanel had not disclosed whether CVE-2026-65643 had been exploited in attacks.

The vulnerability also did not appear in CISA’s Known Exploited Vulnerabilities catalog in the version released on August 27, 2026.

The cPanel notification does not provide an interim mitigation or a method for administrators to determine whether their systems have already been compromised. This makes applying the available security update particularly important for affected hosting environments.

The vulnerability also does not currently have a published CVSS score, and the CVE Program’s record store had not published a record for CVE-2026-65643 when The Hacker News checked on August 28.

cPanel is widely used to manage web hosting environments, where multiple customer accounts can operate on the same physical or virtual server.

A flaw that allows an authenticated customer account to move from limited hosting permissions to root-level code execution can therefore have consequences beyond that individual account. An attacker who successfully exploits the vulnerability could potentially gain control over the underlying server and the other services or accounts hosted on it.

For administrators running affected cPanel & WHM versions, installing the patched build is the recommended course of action.

The available information does not establish that CVE-2026-65643 is being actively exploited, but its critical classification and potential for root-level code execution make timely patching a priority.

Source: The Hacker News

Related articles :


Reports are sourced from official documents, law-enforcement updates, and credible investigations.

Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.