Back to Feed
VulnerabilitiesAug 28, 2026

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Critical cPanel flaw allows root control of servers via domain parking.

Summary

A critical vulnerability in cPanel and WebHost Manager (WHM) allows authenticated users to gain root access to a server by exploiting domain parking and addon domain functionality. Patches have been released for supported versions, and administrators are urged to update immediately. The vulnerability, CVE-2026-65643, could lead to full server compromise.

Full text

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server Swati KhandelwalAug 28, 2026Vulnerability / Web Security cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server. "Successful exploitation leads to code execution as the root user, giving an attacker full control of the server," cPanel said in a notification to customers. cPanel has released the following patched versions - 11.110.0.141 or later 11.134.0.53 or later 11.136.0.37 or later 11.138.0.2 or later 11.138.1.7 or later (WP Squared) The notification names WP Squared in its patched list and does not mention DNSOnly. cPanel patched three separate flaws in July, and the fixed builds named in those advisories included the 11.118 and 11.126 branches. The August 27 list covers the 110, 134, 136, and 138 branches, and the company has not said whether 11.118 and 11.126 remain supported. cPanel said in its July advisory about the Exim flaw that it may allow privilege escalation from Team User sub-accounts. The August 27 notification does not specify whether a Team User sub-account with permission to the parked and addon domains is in scope. Servers configured for automatic daily updates receive the patched build automatically, according to the advisory published on August 27. Administrators can apply it immediately by logging in to the server as root and running /scripts/upcp --force. The update can also be installed from WHM under Home > cPanel > Upgrade to Latest Version, and the installed build can then be verified under Server Configuration > Update Preferences. Servers running an end-of-life version have to upgrade to a supported version to receive the fix. The customer notification carries no CVSS score, and The Hacker News confirmed via the CVE Program's record store on August 28, 2026, that no record has been published for CVE-2026-65643. Records for CVE-2026-58048 and CVE-2026-58047, two cPanel flaws disclosed on July 31, were both present at the time of the check. cPanel has not said whether the flaw has been exploited, and it is absent from the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog as of the version released on August 27, 2026. The catalog already carries two flaws in a cPanel plugin. CISA added CVE-2026-48172, a privilege escalation issue in the LiteSpeed cPanel plugin, on May 26, 2026, and noted that it can be exploited by any cPanel user account to execute arbitrary scripts with root privileges. It added CVE-2026-54420, a symlink-following flaw in the same plugin, on June 15, 2026, for shared hosting servers running CloudLinux or CageFS where a user has FTP or web shell access. The catalog also lists CVE-2026-41940, the authentication bypass patched in April, with known use in ransomware campaigns. The customer notification provides no interim mitigation and no way to verify whether a server has already been compromised. cPanel carried a command to grep the Apache error log for signs of exploitation in its Phusion Passenger advisory, published on August 14, 2026. cPanel said that the issue does not affect default installations and applies only to servers where an affected Passenger package has been installed. Plesk, which WebPros develops alongside cPanel, updated its own advisory for the same flaw on August 14, 2026, with a five-item checklist for spotting a prior compromise that begins with unexpected entries in /etc/ld.so.preload. "Patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done," Plesk said. Phusion, which develops Passenger, shipped a fix in Passenger 6.2.0 on August 18, 2026, for a Watchdog API flaw that does not have a CVE identifier. "We have seen exploitation of this vulnerability in the wild at a shared hosting provider," Phusion said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Arbitrary File Write, Vulnerability, Web Security ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Indicators of Compromise

  • cve — CVE-2026-65643
  • cve — CVE-2026-48172
  • cve — CVE-2026-54420
  • cve — CVE-2026-41940

Entities

cPanel (product)WebHost Manager (WHM) (product)LiteSpeed cPanel plugin (product)Phusion Passenger (product)Plesk (product)WebPros (vendor)