cPanel has patched a critical security flaw that could allow authenticated account holders to execute code as the root user and seize complete control of a server. The vulnerability, designated CVE-2026-65643, affects domain parking and addon domain features across all supported versions of cPanel and WebHost Manager (WHM), according to a notification sent to customers on August 27. The company characterized the issue as critical and said successful exploitation leads to full server takeover.
The flaw allows any authenticated account holder with permission to add parked or addon domains to create arbitrary files on the server, cPanel warned. The company released patches in five separate builds: 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and 11.138.1.7 or later for WP Squared. The August 27 list covers the 110, 134, 136, and 138 branches but does not mention DNSOnly, and cPanel has not clarified whether the 11.118 and 11.126 branches—named in July advisories for three separate flaws—remain supported. Servers configured for automatic daily updates receive the patch automatically, while administrators can apply it immediately by logging in as root and running /scripts/upcp --force, or by installing it from WHM under Home > cPanel > Upgrade to Latest Version.
The customer notification carries no CVSS score, and no CVE record had been published for CVE-2026-65643 as of August 28, 2026, when The Hacker News verified the CVE Program's record store. cPanel provided no interim mitigation and no method to verify whether a server has already been compromised, in contrast to its August 14 Phusion Passenger advisory, which included a command to grep Apache error logs for exploitation signs. The company has not disclosed whether the flaw has been exploited in the wild, and it does not appear in CISA's Known Exploited Vulnerabilities catalog as of August 27, 2026.
The absence of detection guidance and CVSS scoring leaves administrators unable to assess whether their systems were breached before patching, a gap that matters because the vulnerability grants root-level access—the highest privilege tier on Linux servers. Patching closes the vulnerability going forward but does not undo anything an attacker may have already done, as Plesk noted in its own August 14 advisory for the Passenger flaw, which included a five-item checklist for spotting prior compromise. The root user designation means an attacker could install backdoors, exfiltrate data from all hosted accounts, or pivot to other systems without detection, and the lack of forensic tools in cPanel's notification compounds the risk for shared hosting providers managing thousands of customer accounts on single servers.
Servers running end-of-life versions must upgrade to a supported build to receive the fix, and administrators can verify the installed version under Server Configuration > Update Preferences. The timing matters: CISA has already catalogued three cPanel-related flaws this year, including CVE-2026-48172 and CVE-2026-54420 in the LiteSpeed plugin—both privilege escalation issues added in May and June—and CVE-2026-41940, an authentication bypass patched in April with known use in ransomware campaigns. Phusion shipped a fix for a separate Watchdog API flaw in Passenger 6.2.0 on August 18, noting it had seen exploitation in the wild at a shared hosting provider, underscoring the urgency for immediate patching across the ecosystem. Hosting providers face a narrow window to act before exploit code circulates, particularly given the authenticated nature of the flaw means any compromised customer account becomes a foothold for server-wide takeover. The lack of clarity on Team User sub-account scope and the silence on exploitation status suggest cPanel may still be assessing the full blast radius while urging customers to patch without delay.

