Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, cpanel, whm, web-hosting, shared-hosting, arbitrary-file-write, rce, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

CVE-2026-65643

CVE-2026-65643 is a critical vulnerability in the domain-parking and addon-domain functionality of cPanel and WebHost Manager (WHM), affecting all supported versions. An authenticated account holder who can add parked or addon domains can create arbitrary files on the server, leading to code execution as the root user and full compromise of the hosting server. cPanel has described successful exploitation as giving an attacker full control of the server.

The vendor released patches in builds 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and 11.138.1.7 or later. It is the second critical cPanel/WHM issue of 2026, following the authentication-bypass flaw CVE-2026-41940 that the ACSC flagged for active exploitation in Australia in May. For shared-hosting operators the flaw matters because a single compromised customer account can escalate to root across the whole server, and most Australian exposure in the hosting market sits in this shared-hosting model.

Source