A newly disclosed cPanel and WHM vulnerability can turn an ordinary hosting account into root-level control of the underlying server. Tracked as CVE-2026-65643, the flaw affects the domain-parking feature and allows an authenticated, low-privileged user to create files in arbitrary locations. cPanel says that capability can lead to code execution as root.
Routine hosting access becomes a server-wide threat
Domain parking lets customers direct additional domain names to an existing website without creating separate hosting accounts. The feature is common across shared and reseller environments. An attacker needs a valid cPanel account that can add parked or addon domains, but does not require administrator credentials or a complex chain of additional vulnerabilities.
That prerequisite is a relatively low barrier. A threat actor could purchase an inexpensive shared-hosting plan or take over an existing customer’s credentials. Once arbitrary files can be placed outside the account’s expected boundaries, the attacker can cross the separation between tenants and execute code with the highest operating-system privileges.
Impact extends to every tenant on the host
On a multi-tenant server, root compromise is not limited to the account used for the attack. Other websites, databases, mailboxes, configuration files and credentials on the machine may become accessible. An intruder could steal customer data, alter sites, deploy malware or use the trusted server as infrastructure for attacks elsewhere.
Hosting providers face additional downstream consequences because a single compromised customer can affect many unrelated organizations. Incident response may require isolating the host, assessing every tenant, rotating secrets and restoring from known-good systems. Rapid patching is therefore far less disruptive than responding after exploitation.
Patched cPanel and WHM builds
The vulnerability affects all currently supported cPanel and WHM versions, according to the disclosure. Fixed builds are available across the active release tiers: 11.110.0.141, 11.134.0.53, 11.136.0.37 and 11.138.0.2 or later. Systems on the WP2 track should run build 11.138.1.7 or later.
End-of-life branches do not receive these fixes. Administrators still operating an unsupported version must first migrate to a supported line. Although cPanel commonly delivers automatic updates, providers with manual policies, pinned versions or custom release schedules should not assume deployment has completed.
- Inventory every cPanel and WHM server and record its exact build number.
- Update to a fixed build and confirm the running version after any required restart.
- Temporarily restrict parked and addon-domain permissions on systems awaiting updates.
- Review recently added domains and unexpected filesystem changes for signs of abuse.
- Investigate suspicious root-level processes, persistence and access across tenant accounts.
Hardening shared-hosting environments
Providers should consider the patch the immediate control and permission review a useful temporary safeguard. Longer term, centralized asset tracking can identify servers that missed automatic updates, while file-integrity monitoring can reveal changes in sensitive system paths. Administrative actions and customer domain changes should be logged centrally so an attacker cannot easily erase the only evidence.
Teams should also prepare an incident plan for cross-tenant compromise. That includes preserving disk and audit evidence, identifying credentials stored on the host, notifying affected customers and rebuilding systems when root integrity cannot be trusted. Restoring only one customer account would be insufficient after server-wide privilege escalation.
Resellers should verify downstream infrastructure rather than relying solely on upstream assurances. Providers can make remediation easier to audit by exporting version reports and associating each host with an accountable owner. Where customer permissions were temporarily reduced, those permissions should be restored only after patch confirmation and a review of recent domain activity.
Public disclosure often shortens the time before opportunistic scanning begins. Hosting companies and administrators should verify patched builds now rather than relying on update assumptions. This article is based exclusively on Cyber Security News reporting published on August 28, 2026.
Leave a Reply
You must be logged in to post a comment.