cPanel Flaw Enables Root Takeover of Shared Hosting Servers
A critical vulnerability in cPanel and WHM allows any authenticated user to escalate privileges to root level by abusing domain parking and addon domain features — functionality present in virtually every shared hosting environment. This is particularly dangerous because shared hosting servers house multiple customers, meaning one malicious or compromised account could expose every other tenant on the same server. The flaw highlights the risk of privilege escalation vulnerabilities in widely-deployed hosting control panels that are often slow to be patched by hosting providers. Because cPanel is ubiquitous in web hosting, the attack surface is enormous, and delayed patching leaves entire hosting infrastructures — and their customers — critically exposed.
Tactical Insight
Immediate actions
- Apply the latest cPanel/WHM patches immediately and verify the installed version against vendor advisories for CVE-2026-65643.
- Audit all authenticated cPanel user accounts and revoke or suspend any suspicious or unnecessary accounts until patching is confirmed complete.
- Temporarily restrict addon domain and domain parking functionality if the patch cannot be applied immediately.
Long-term improvements
- Implement an automated patch management pipeline that prioritises and fast-tracks critical severity vulnerabilities in internet-facing control panel software.
- Enforce the principle of least privilege across all hosting accounts, ensuring users cannot access resources or features beyond their designated scope.
- Maintain a current inventory of all hosting infrastructure versions to enable rapid impact assessment when new CVEs are disclosed.
Detection measures
- Deploy file integrity monitoring and privilege escalation alerting to detect unexpected root-level activity on hosting servers.
- Enable centralised logging of cPanel/WHM authentication and domain management events, and alert on anomalous patterns such as unusual addon domain creation.
- Conduct regular penetration tests targeting privilege escalation paths within shared hosting environments.