cPanel has urgently addressed a significant security flaw that could potentially allow unauthorized users to gain root access to a server. The vulnerability, identified as CVE-2026-65643, affects all supported versions of cPanel and WebHost Manager (WHM). This issue involves a security gap in the domain parking and addon domain functionality that could lead to arbitrary code execution.
Details of the Vulnerability
According to cPanel, the flaw is categorized as critical, enabling authenticated users with the ability to add parked or addon domains to create arbitrary files on the server. If exploited, this could result in an attacker obtaining complete control over the server by executing code as the root user.
The company has released several updated versions to address this issue, including versions 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7. Notably, WP Squared is included in this patch list, while DNSOnly is not mentioned.
Impact and Advisory
Previously, cPanel fixed other vulnerabilities in July, and those updates included versions 11.118 and 11.126. However, the latest advisory does not confirm whether these branches remain supported. The flaw has not been listed in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog as of the latest update.
Servers configured for automatic daily updates will receive the patched versions automatically. Administrators can also manually apply the updates by executing specific commands or through the cPanel interface. Systems running outdated versions must upgrade to supported versions to receive the necessary security fixes.
Future Outlook and Recommendations
Currently, there is no interim mitigation provided by cPanel to verify if a server has been compromised. Users are encouraged to apply the patches immediately to prevent potential exploitation. Despite the absence of a CVSS score, the urgency conveyed in cPanel’s communications underlines the severity of this flaw.
In addition, cPanel has shared a command to inspect Apache error logs for any signs of exploitation, particularly in cases involving the Phusion Passenger package. Users are advised to remain vigilant and ensure that their systems are updated regularly to protect against such critical vulnerabilities.
As cybersecurity threats continue to evolve, maintaining updated software and following best practices are essential for safeguarding server environments against potential breaches.
