cPanel fixes critical flaw enabling root code execution

cPanel has released fixes for CVE-2026-65643, a critical vulnerability in cPanel & WebHost Manager (WHM) that could allow an authenticated hosting customer to execute code as root. The issue affects all supported versions of the platform and involves domain parking and addon-domain functionality.
cPanel said an account holder with permission to add parked or addon domains could create arbitrary files on the server. Successful exploitation could lead to root-level code execution, giving an attacker full control of the affected server.
Patched versions and update paths
The company listed the following fixed builds: 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and WP Squared 11.138.1.7 or later. The notification includes WP Squared but does not mention DNSOnly.
Servers configured for automatic daily updates should receive a patched build automatically. Administrators can also update immediately by logging in as root and running /scripts/upcp --force. In WHM, the update is available through Home > cPanel > Upgrade to Latest Version, with the installed build verifiable under Server Configuration > Update Preferences.
Systems running end-of-life releases must first move to a supported version before they can receive the fix. The August 27 patched-build list covers the 11.110, 11.134, 11.136 and 11.138 branches. cPanel has not stated whether the 11.118 and 11.126 branches named in July advisories remain supported.
What remains unknown
The customer notification did not include a CVSS score. As of August 28, 2026, no CVE Program record had been published for CVE-2026-65643, despite records being available for CVE-2026-58048 and CVE-2026-58047, two cPanel flaws disclosed on July 31.
cPanel has not said whether CVE-2026-65643 has been exploited. It was also absent from the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog in the version released on August 27. The advisory does not clarify whether a Team User sub-account with the relevant domain permissions falls within the affected access model.
Operational implications for hosting teams
The notification provides neither an interim mitigation nor a method to establish whether an attacker compromised a server before patching. That limitation is material in shared-hosting environments, where a customer-level capability may be exposed to many users with different administrative permissions.
Hosting operators should confirm the running cPanel & WHM build, apply a listed fixed release without delay, and identify accounts permitted to manage parked or addon domains. Because patching closes the vulnerability going forward but does not establish whether it was previously abused, teams should also assess their existing server-review and incident-response procedures.

