VYPR
patchPublished Aug 28, 2026· 1 source

Critical cPanel Vulnerability Allows Attackers to Take Full Server Control

A critical vulnerability (CVE-2026-65643) in cPanel and WHM allows low-privileged authenticated users to gain root-level control of a server by exploiting the domain parking functionality.

A critical vulnerability, CVE-2026-65643, has been disclosed in cPanel and WHM, the widely adopted web hosting control panel software. This flaw could allow a low-privileged, authenticated user to gain complete root-level control over an entire server. The vulnerability resides within cPanel's domain parking functionality, a common feature that enables hosting customers to point additional domain names to an existing website without needing to set up a separate account. This means the affected functionality is present on a vast number of shared and reseller hosting environments that utilize cPanel.

The exploit requires only a legitimate, low-tier cPanel login with permissions to add parked or addon domains. Once access is gained, an attacker can leverage the flaw to create arbitrary files anywhere on the server's file system. This capability bypasses typical security restrictions and does not necessitate advanced exploitation skills or chained vulnerabilities. The ease of access, combined with the powerful arbitrary file creation, makes this a significant threat.

Successful exploitation of CVE-2026-65643 leads to code execution with root privileges, effectively granting an attacker full administrative control over the compromised machine. On a shared hosting server, this single compromised account poses a risk to every other website, database, and email account hosted on the same infrastructure. For hosting providers, a malicious or compromised customer could pivot from their limited account to a full server takeover, enabling actions such as defacing websites, stealing sensitive customer data, deploying malware, or using the server as a launchpad for further attacks across the provider's network.

cPanel has confirmed that all currently supported versions of cPanel and WHM are affected by this vulnerability. The company has responded by releasing patched builds across all active release tiers. Specific patched versions include 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, and 11.138.0.2 or later. For servers running the WP2 update track, patched build 11.138.1.7 or later is available.

Administrators managing older, end-of-life branches of cPanel and WHM are not covered by these fixes and remain vulnerable unless they upgrade to a supported version. Given the critical nature of the vulnerability and the low barrier to exploitation, cPanel urges hosting providers and system administrators to treat this as an urgent, high-priority patch. While cPanel typically pushes automatic updates, manual update policies or custom schedules require administrators to verify their build numbers and apply updates promptly.

In addition to patching, hosting providers are advised to review which customer accounts have permissions to add parked or addon domains. Temporarily restricting this capability on servers awaiting patch deployment could serve as an additional mitigation measure. The widespread use of cPanel in shared and reseller hosting environments means that the window between public disclosure and potential mass exploitation is often narrow, making rapid patching the most critical defense.

This vulnerability highlights the ongoing challenges in securing shared hosting environments, where a single misconfiguration or flaw can have cascading effects across multiple tenants. The ability for a low-privileged user to escalate to root privileges underscores the importance of robust access controls and timely security updates for all software components, especially those managing critical infrastructure.

Synthesized by Vypr AI