Back to advisories

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/WHM, assume your multitenancy isolation is broken until patched.

CRITICALAdvisoryAug 28, 2026
Action required
Immediately patch all cPanel and WHM instances to patched versions. For unpatched systems, restrict addon domain and domain parking functionality at the account level until patches are deployed.
Affected products
cPanelWebHost Manager (WHM)LiteSpeed cPanel pluginPhusion PassengerPlesk