Posted in

cPanel Patches Critical Flaw That Could Give Attackers Root Access

cPanel has released security updates for a critical vulnerability in its cPanel & WebHost Manager (WHM) platform that could allow an authenticated user to execute arbitrary code with root privileges on an affected server.

Tracked as CVE-2026-65643, the vulnerability affects supported versions of cPanel & WHM and is related to the platform’s parked domain and addon domain functionality.

According to cPanel, an authenticated account holder with permission to add parked or addon domains could exploit the flaw to create arbitrary files on the server.

“Successful exploitation leads to code execution as the root user, giving an attacker full control of the server,” cPanel said in a customer security notification.

Because successful exploitation can result in complete server compromise, administrators are urged to install the available updates as soon as possible.

cPanel Releases Security Updates

cPanel has released patched builds for the following versions:

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • 11.138.1.7 or later for WP Squared

The August 27 security notification specifically includes WP Squared in the list of patched products but does not mention DNSOnly.

The company has not provided details indicating whether the vulnerability affects DNSOnly installations.

Who Can Exploit CVE-2026-65643?

The vulnerability requires an attacker to have an authenticated account and the ability to add parked or addon domains.

This means the flaw is not described as an unauthenticated remote attack. However, on shared hosting environments where multiple customers have accounts on the same server, a compromised or malicious account could potentially become a serious security risk.

cPanel has not publicly detailed the exact exploitation chain beyond stating that an authorized account holder can create arbitrary files, ultimately leading to root-level code execution.

The company also has not clarified whether Team User sub-accounts with the relevant permissions are affected.

That question is notable because cPanel disclosed another vulnerability in July that could allow privilege escalation from Team User sub-accounts.

Administrators Should Update Immediately

Servers configured to perform automatic daily updates should receive the patched build automatically, according to cPanel’s August 27 notification.

Administrators who want to apply the update immediately can log in to the server as root and run:

/scripts/upcp --force

The update can also be installed through WHM by navigating to:

Home → cPanel → Upgrade to Latest Version

After updating, administrators can verify the installed build through:

Server Configuration → Update Preferences

Servers running an end-of-life cPanel version must first upgrade to a supported release before they can receive the security fix.

No CVSS Score or CVE Record Yet

cPanel’s customer notification does not provide a CVSS severity score for CVE-2026-65643.

A check of the CVE Program’s record store on August 28, 2026, also found that no public CVE record had yet been published for the vulnerability.

For comparison, records for CVE-2026-58048 and CVE-2026-58047, two cPanel vulnerabilities disclosed on July 31, were already available at the time of the check.

The absence of a public CVSS score or CVE record does not reduce the potential severity of the issue. cPanel itself classifies CVE-2026-65643 as a critical security vulnerability because exploitation can result in root-level code execution.

No Known Exploitation Reported

cPanel has not said whether CVE-2026-65643 has been exploited in real-world attacks.

The vulnerability was also not listed in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) Catalog in the version released on August 27, 2026.

However, the CISA catalog already includes other vulnerabilities affecting the cPanel ecosystem.

Other cPanel Vulnerabilities Added to CISA’s KEV Catalog

CISA added CVE-2026-48172 on May 26, 2026. The flaw affects the LiteSpeed cPanel plugin and can allow a cPanel user account to execute arbitrary scripts with root privileges.

On June 15, CISA added CVE-2026-54420, another vulnerability in the LiteSpeed cPanel plugin. The issue involves symlink following and affects certain shared hosting environments running CloudLinux or CageFS when users have FTP or web shell access.

CISA has also listed CVE-2026-41940, an authentication bypass vulnerability patched in April, after identifying its use in ransomware campaigns.

cPanel Provides No Compromise-Detection Guidance

The August 27 notification does not provide an interim mitigation for CVE-2026-65643.

It also does not give administrators a specific method for determining whether the vulnerability has already been exploited on their servers.

That distinction is important because installing a security update prevents future exploitation but does not remove malicious files, accounts, persistence mechanisms or other changes that an attacker may have already made.

Administrators who suspect their systems may have been compromised should therefore consider reviewing authentication logs, account activity, recently created files and other indicators of unauthorized access in addition to installing the security update.

Separate Passenger Vulnerability Also Under Investigation

The cPanel update comes shortly after another security issue involving Phusion Passenger, a web application server commonly used in hosting environments.

In an August 14, 2026 advisory, cPanel included a command for searching Apache error logs for potential signs of exploitation related to the Passenger issue.

cPanel said that vulnerability does not affect default installations and applies only to servers where an affected Passenger package has been installed.

Plesk, another hosting-control platform developed by WebPros, also updated its advisory for the same Passenger vulnerability on August 14.

Plesk provided administrators with a five-step checklist for identifying potential prior compromise. The process begins with checking for unexpected entries in:

/etc/ld.so.preload

Plesk emphasized that installing a patch does not address activity that may have occurred before the vulnerability was fixed.

“Patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done,” Plesk said.

Phusion Confirms In-the-Wild Exploitation

Phusion, the company behind Passenger, released Passenger 6.2.0 on August 18, 2026, to address a Watchdog API vulnerability that does not currently have a CVE identifier.

Phusion said the vulnerability had already been exploited in the wild at a shared hosting provider.

The disclosure highlights the risks faced by shared hosting environments, where a single compromised account or vulnerable component can potentially provide attackers with a pathway to additional systems or higher privileges.

What cPanel Administrators Should Do

Administrators running supported cPanel & WHM installations should:

  • Update to a patched cPanel build immediately.
  • Verify that automatic updates are enabled and functioning correctly.
  • Confirm the installed version after the update.
  • Review account activity if suspicious behavior has been observed.
  • Investigate unexpected files, processes or configuration changes.
  • Pay particular attention to servers hosting multiple customer accounts.
  • Review logs for unusual authentication and domain-management activity.
  • Treat systems running end-of-life cPanel releases as a priority for upgrade.

Because CVE-2026-65643 can potentially lead to root-level code execution, delaying the update could leave an affected hosting server exposed to complete compromise.

Administrators should also remember that patching only addresses future exploitation. If there is evidence that an attacker may already have gained access, the server should be investigated for signs of compromise rather than assuming the update alone has resolved the incident.

Leave a Reply

Your email address will not be published. Required fields are marked *