CVE-2026-65643: Privilege Escalation in CPanel/WHM Domain Parking and Addon Domain Modules

Last Updated: 2026-08-29T15:02:56Z

CVSSv3: None Yet

An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server…lead[ing] to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.

This has a severe impact for multi-tenant hosting exposing:

  • Private website files and source code
  • Customer databases and sensitive records
  • Private email accounts and communications
  • System configuration files and credentials
  • Server-wide backups and logs

Affected Versions

This vulnerability affects all supported versions of cpanel and WHM. These are the patched builds you should update to using the upcp script or the WHM interface:

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • WP2: 11.138.1.7 or later

Actions

If you can’t update, stop users from adding new parked or addon domains.

Additional Sources

CVE Tracking: https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Vulnerability-in-cPanel-s-Domain-Parking-Functionality-August-27-2026

1 Like

As far as I know there is no confirmation of exploitation. However, I am aware of two separate incidents where the compromise of an account in a shared hosting environment (which was based on cPanel) ultimately lead to full takeover of the affected host systems. The incidents were especially interesting because it wasn’t entirely clear how the move from compromised user account to full takeover happened - but everything in those incidents would, at least roughly, fit for this issue.

Again, I can’t confirm it definitely, but I would treat this as ‘actively exploited’, just to be on the safe side.

2 Likes