Back to Security Advisories

Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality – August 27, 2026

An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.

High 8.8 CVSS
cPanel

Default Update CMD

sudo /scripts/upcp --force

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • WP2: 11.138.1.7 or later

Impact

Successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

Frequently Asked Questions

What is CVE-2026-65643?
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Is CVE-2026-65643 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.9% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-65643?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System