PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65643 cPanel CVE debrief

The CVE-2026-65643 vulnerability in cPanel's Domain Parking Functionality allows an authenticated cPanel account holder who can add parked or addon domains to create arbitrary files on the server. This can lead to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it. The vulnerability affects all supported versions of cPanel/WHM. Patched versions are available, including 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and WP2: 11.138.1.7 or later. cPanel/WHM users and administrators should be aware of this vulnerability and take immediate action to update to patched versions to prevent potential exploitation.

Vendor
cPanel
Product
cPanel/WHM
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-24
Original CVE updated
2026-08-27
Advisory published
2026-08-24
Advisory updated
2026-08-27

Who should care

cPanel/WHM users and administrators, as well as operators, platforms, vulnerability-management teams, and security teams, should be aware of this vulnerability and take immediate action to update to patched versions to prevent potential exploitation. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed. Additionally, compensating controls for exposed systems should be reviewed while remediation is scheduled and verified, and relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retesting of remediated assets, and closing the item only after evidence is documented are also crucial steps to take. Asset inventory and source tracking are important for verifying the vulnerability and ensuring that all affected systems are addressed. Rollback/change windows should be considered for updates to minimize potential disruptions. Monitoring and detection capabilities should be in place to identify potential exploitation attempts. Compensating controls, such as additional security measures, may be necessary for exposed systems until remediation can be verified. The vulnerability's impact on the organization depends on the specific use of cPanel/WHM and the potential for lateral movement within the network. Therefore, a thorough review of the environment and affected systems is necessary to determine the full scope of the vulnerability and required actions. This may involve coordination with multiple teams, including IT, security, and compliance, to ensure that all necessary steps are taken to mitigate the vulnerability and prevent potential exploitation. Furthermore, it is essential to track the vulnerability's status and remediation progress to ensure that all affected systems are addressed and that the vulnerability is properly closed out. This includes documenting evidence of remediation and verifying that all necessary steps have been taken to prevent potential exploitation. By taking these steps, organizations can help prevent the CVE

Technical summary

The CVE-2026-65643 vulnerability allows an authenticated cPanel account holder who can add parked or addon domains to create arbitrary files on the server. Successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it. Affected product versions include all supported versions of cPanel/WHM. Patched versions are available, including 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and WP2: 11.138.1.7 or later.

Defensive priority

cPanel/WHM users should prioritize updating to patched versions to prevent potential code execution as the root user.

Recommended defensive actions

  • Update cPanel/WHM to version 11.110.0.141 or later
  • Update cPanel/WHM to version 11.134.0.53 or later
  • Update cPanel/WHM to version 11.136.0.37 or later
  • Update cPanel/WHM to version 11.138.0.2 or later
  • Update cPanel/WHM to version WP2: 11.138.1.7 or later

Evidence notes

The CVE-2026-65643 vulnerability allows an authenticated cPanel account holder to create arbitrary files on the server, potentially leading to code execution as the root user. Affected product versions include all supported versions of cPanel/WHM. Patched versions are available, including 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and WP2: 11.138.1.7 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-65643 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-65643

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-65643 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65643

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.