A newly identified security flaw in cPanel and WHM, a popular web hosting control panel, could permit attackers with minimal privileges to obtain root access to an entire server.
CVE-2026-65643: A Threat to Server Security
Designated CVE-2026-65643, this vulnerability was disclosed in an advisory on August 27, 2026, by cPanel support engineer Devon Courtney. The flaw is located within the domain parking feature of cPanel, which allows authenticated users to create arbitrary files on the server.
The vulnerability is particularly concerning because it requires only a basic cPanel account with permission to add parked or addon domains. This makes it possible for attackers to exploit the bug using a simple shared hosting account or a compromised user login.
Implications for Hosting Environments
Domain parking, a common feature in web hosting, lets users direct additional domains to an existing site without needing separate accounts. This functionality is widespread across shared and reseller hosting services using cPanel, making the vulnerability especially dangerous.
By exploiting this flaw, attackers can execute code as the root user, gaining control of the entire server. This not only jeopardizes the compromised account but also every other site, database, and email hosted on the same server.
Urgent Need for Patch Implementation
cPanel has responded by releasing patches for all supported versions, including builds 11.110.0.141 and later. However, administrators using outdated versions must upgrade to receive these fixes.
Hosting providers and system administrators are urged to prioritize this patch due to the simplicity of the required exploit. While cPanel typically updates automatically, those handling manual updates must ensure they are running the patched versions immediately.
Additionally, reviewing account permissions for domain additions and restricting them temporarily can help mitigate risk until the patch is applied.
Given cPanel’s prevalence in hosting, the time between vulnerability disclosure and exploitation can be brief, emphasizing the need for swift action to protect server integrity.
