Critical cPanel Vulnerability (CVE-2023-XXXX) Allows Full Server Control
Key Takeaways A critical vulnerability, CVE-2026-65643, has been discovered in cPanel and WHM. The flaw allows a low-privileged, authenticated user to achieve root-level control over a server. The...
Key Takeaways
- A critical vulnerability, CVE-2026-65643, has been discovered in cPanel and WHM.
- The flaw allows a low-privileged, authenticated user to achieve root-level control over a server.
- The vulnerability resides in the domain parking functionality, a common feature in shared hosting environments.
- Patches are available for all supported cPanel and WHM versions.
- Immediate patching is strongly recommended to prevent widespread exploitation.
Critical cPanel Flaw Grants Full Server Control
A severe security vulnerability has been identified in cPanel and WHM, the ubiquitous web hosting control panel software. This newly disclosed flaw could enable an authenticated user with minimal privileges to escalate their access and gain complete root control of the entire server.
Table Of Content
Details of the Vulnerability
Designated as CVE-2026-65643, the critical vulnerability is located within cPanel’s domain parking feature. The details of this flaw were made public in an advisory issued on August 27, 2026, by cPanel support engineer Devon Courtney.
According to the advisory, any cPanel account holder who possesses the authorization to add parked or addon domains can exploit this bug. The successful exploitation allows the creation of arbitrary files at any location on the underlying server. This capability is particularly dangerous because domain parking is a standard function, allowing hosting clients to direct additional domain names to an existing website without requiring a separate hosting account. Consequently, this vulnerable functionality is prevalent across virtually all shared and reseller hosting environments utilizing cPanel.
High Impact, Low Barrier to Exploitation
The arbitrary file creation capability significantly lowers the bar for exploitation. Attackers do not need sophisticated exploitation techniques or additional chained vulnerabilities. Access to a legitimate, low-tier cPanel login — which can be easily acquired through a low-cost shared hosting plan or a compromised customer account — is sufficient.
The true gravity of this flaw stems from what arbitrary file creation facilitates. cPanel has confirmed that successful exploitation directly leads to code execution with root privileges, effectively handing an attacker full control over the server. In a shared hosting environment, this means that a single compromised account doesn’t just put itself at risk; every other website, database, and email account hosted on that same server becomes exposed.
For hosting providers managing multi-tenant infrastructure, this vulnerability presents a profound risk. A single malicious or compromised customer account could pivot from its limited scope to a complete server takeover. Such an compromise could lead to website defacement, theft of sensitive customer data, deployment of malware, or the use of the server as a launchpad for further attacks across the provider’s network.
Patch Availability and Urgency
cPanel states that the vulnerability affects all currently supported versions of cPanel and WHM. The company has promptly released patched builds across all active release tiers:
- Version 11.110.0.141 or later
- Version 11.134.0.53 or later
- Version 11.136.0.37 or later
- Version 11.138.0.2 or later
- WP2 build 11.138.1.7 or later (for servers on that update track)
It is crucial to note that administrators operating older, end-of-life branches of cPanel will not receive these fixes and will remain vulnerable unless they upgrade to a supported version first.
Given the ease of exploitation, requiring only an authenticated account with domain-parking permissions, hosting providers and system administrators must treat this as an urgent, high-priority patching requirement. While cPanel typically deploys automatic updates, administrators with manual update policies or custom deployment schedules should immediately verify their build numbers against the patched versions and apply updates without delay. Due to cPanel’s widespread use in shared and reseller hosting, the window between public disclosure and attempts at mass exploitation is typically very narrow, making rapid patching the most effective defense.
What You Should Do
- Apply Patches Immediately: Ensure all cPanel and WHM installations are updated to the latest patched versions (11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, or WP2 build 11.138.1.7+).
- Upgrade Unsupported Versions: If running an end-of-life cPanel version, upgrade to a supported branch before applying the patch.
- Review Account Permissions: Temporarily review and consider restricting the ability for customer accounts to add parked or addon domains on servers awaiting patch deployment.
- Verify Automatic Updates: Even with automatic updates enabled, confirm that the patches have been successfully applied by checking your cPanel/WHM version number.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.