Critical

cPanel, WHM, CVE-2026-65643, RCE, Web Hosting, Privilege Escalation

cPanel CVE-2026-65643: One Account to Root the Server

cPanel CVE-2026-65643 lets an authenticated account with addon domain access run code as root and take over the whole server. Affected versions and the fix.

cPanel CVE-2026-65643 is a critical vulnerability in cPanel and WebHost Manager (WHM) that lets an authenticated account holder, one who can add parked or addon domains, create arbitrary files on the server and execute code as the root user, taking full control of the machine. It affects all supported versions of cPanel and WHM, and cPanel has released patched builds. On shared hosting, where many customers share one server, a single low-privileged tenant escalating to root is close to a worst case, because it turns one compromised account into control of every site on the box.

cPanel described the flaw in the domain parking and addon domain functionality, and the escalation path is direct: an account that can add parked or addon domains can write arbitrary files, and successful exploitation yields code execution as root. This lands in a busy patch season for cPanel, which fixed three separate flaws in July, including an Exim issue the company said may allow privilege escalation from Team User sub-accounts. Whether a Team User sub-account with domain permissions is in scope for this new flaw was not specified.

Which cPanel and WHM versions are affected and fixed?

All supported versions are affected, and the fix is to update to a patched build. Servers configured for automatic daily updates receive it automatically; administrators can also apply it immediately by logging in as root and running /scripts/upcp --force, or installing it from WHM.

Item

Detail

CVE

CVE-2026-65643

Affected

All supported cPanel and WHM versions

Component

Domain parking and addon domain functionality

Impact

Authenticated account creates arbitrary files, code execution as root

Fixed builds

11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, 11.138.1.7+ (WP Squared)

Fast patch

Run /scripts/upcp --force as root, or update from WHM

Why does this matter so much for shared hosting?

Because the trust boundary between tenants is the entire product. Shared hosting sells the promise that your neighbor cannot reach your files, and a root-level escalation from an ordinary account breaks that promise for everyone on the server at once. Hosting providers and anyone running multi-tenant cPanel should treat this as urgent, since the population of "authenticated account holders who can add domains" is, by design, large and not fully trusted.

Our read

A flaw that turns one tenant into root of a whole server is the defining risk of multi-tenant infrastructure, and it does not require an external attacker to start, only an account. That makes patch speed the whole game here: the window between disclosure and a customer or attacker testing the escalation is short. The continuous-verification posture is to confirm every cPanel and WHM server is actually on a fixed build rather than trusting that auto-update ran, because on shared hosting the cost of one missed server is measured in every site it hosts.

Reporting by The Hacker News; affected-version and patch detail per the cPanel advisory. Sources linked above.

Related: How to prioritize vulnerabilities and Code security for SMBs.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.