HackMyIP
← Back to News
2026-08-28 The Hacker News

Critical cPanel Flaw Lets Hosting Customers Execute Code as Root

VulnerabilityAuthenticationCloud Security

cPanel has rolled out emergency patches for a critical security vulnerability (CVE-2026-65643) affecting its domain parking and addon domain functionality in cPanel and WebHost Manager (WHM). The flaw enables an authenticated hosting customer to create arbitrary files on the server, ultimately leading to code execution as the root user and full compromise of the underlying infrastructure. The issue impacts all currently supported versions of the platform, making it a pressing concern for shared hosting providers and their tenants.

The patched builds are now available across four release lines: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 for WP Squared installations. Servers configured for automatic daily updates will receive the fix without manual intervention, while administrators can apply it immediately by running /scripts/upcp --force as root or via WHM's Upgrade to Latest Version interface. Notably, cPanel's August 27 notification does not confirm whether the older 11.118 and 11.126 branches remain supported, nor does it clarify whether Team User sub-accounts with parked or addon domain permissions fall within the exploitation scope, a gap that follows the company's July disclosure of a separate Exim flaw that allowed privilege escalation from those sub-accounts.

As of August 28, 2026, no CVSS score had been assigned, and the CVE Program's record store had not yet published an entry for CVE-2026-65643, though records for the two cPanel flaws disclosed on July 31 (CVE-2026-58048 and CVE-2026-58047) were already present. cPanel has not confirmed any in-the-wild exploitation, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. That catalog does, however, already contain two earlier flaws in a cPanel plugin: CVE-2026-48172, a privilege escalation issue in the LiteSpeed cPanel plugin allowing any cPanel user to execute arbitrary scripts as root, and CVE-2026-54420, a symlink-following vulnerability on shared hosting servers running CloudLinux or CageFS. Hosting providers and system administrators should prioritize patching immediately and review their environments for signs of compromise, beginning with a thorough audit of parked and addon domain records and the underlying server configurations. Administrators can validate exposed services and certificates using our SSL/TLS checker and port scanner, while domain holders can confirm registration details through our WHOIS lookup tool.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →