A newly disclosed vulnerability in cPanel and WHM, the widely used web hosting control panel software, could let a low-privileged, authenticated user seize root-level control of an entire server.
Tracked as CVE-2026-65643, the flaw resides in cPanel’s domain parking functionality and was publicly detailed in an advisory published on August 27, 2026, by cPanel support engineer Devon Courtney.
According to the advisory, any authenticated cPanel account holder who has permission to add parked or addon domains can exploit the bug to create arbitrary files anywhere on the underlying server.
Domain parking is a routine feature that lets hosting customers point additional domain names to an existing website without setting up a separate account, which means the affected functionality is enabled on virtually every shared and reseller hosting environment running cPanel.
Because the flaw allows arbitrary file creation, an attacker does not need advanced exploitation skills or additional chained bugs to abuse it, only a legitimate, low-tier cPanel login, something easily obtained through a cheap shared hosting plan or a compromised customer account.
The real danger lies in what that arbitrary file creation enables. cPanel confirms that successful exploitation leads to code execution as the root user, effectively handing an attacker the keys to the entire machine.
On a shared hosting server, that single compromised account is not just at risk itself; every other website, database, and email account hosted on the same box becomes exposed.
For hosting providers running multi-tenant infrastructure, a single malicious or compromised customer could pivot from their own limited account into a full server takeover, potentially defacing sites, stealing customer data, deploying malware, or using the server as a launchpad for further attacks across the provider’s network.
cPanel states that the vulnerability affects all currently supported versions of cPanel and WHM. The company has released patched builds across every active release tier: version 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, and 11.138.0.2 or later, along with WP2 build 11.138.1.7 or later for servers running that update track.
Administrators running older, end-of-life branches are not covered by these fixes and remain exposed unless they upgrade to a supported version first.
Given that exploitation requires only an authenticated account with domain-parking privileges, hosting providers and system administrators should treat this as an urgent, high-priority patch.
cPanel typically pushes automatic updates, but administrators managing manual update policies or custom deployment schedules should verify their build number against the patched versions immediately and apply updates without delay.
Providers should also review which customer accounts have permission to add parked or addon domains and consider temporarily restricting that capability on servers awaiting patch deployment.
Given cPanel’s dominance in shared and reseller hosting, the window between public disclosure and mass exploitation attempts is typically short, making rapid patching the single most effective defense against this vulnerability.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents…