Panellicense

CVE-2026-65643: patch the cPanel domain parking root vulnerability

CVE-2026-65643 lets an authenticated cPanel user with parked or addon-domain access create arbitrary server files and potentially execute code as root. Check the fixed builds and update now.

cPAll cPanel articlesNews & changelogs3 min readUpdated 2026-08-27
schema: TechArticleschema: FAQPageschema: BreadcrumbList

cPanel has released emergency builds for CVE-2026-65643, a critical vulnerability in cPanel & WHM's domain parking functionality. An authenticated cPanel account that can add parked or addon domains may be able to create arbitrary files on the server. Successful exploitation can lead to code execution as root and complete server compromise.

All supported cPanel & WHM versions were listed as affected in cPanel's 27 August 2026 security advisory. Do not assume that restricting WHM access protects the server: the vulnerable operation is available to ordinary cPanel accounts when their feature permissions allow domain aliases or addon domains.

Affected and patched builds

Update to at least the fixed build for your branch:

cPanel & WHM branchFirst patched build
11.11011.110.0.141
11.13411.134.0.53
11.13611.136.0.37
11.13811.138.0.2
WP Squared 11.138.111.138.1.7

A later build in the same supported branch also contains the fix. If the server is on an end-of-life branch, move it to a supported release; an unsupported installation cannot be considered patched merely because automatic updates are enabled.

Check the installed cPanel version

Run this as root:

/usr/local/cpanel/cpanel -V

Compare the complete version with the table above. For example, 11.136.0.36 remains vulnerable, while 11.136.0.37 or later in that branch contains the hotfix.

You can also check in WHM under Server Configuration > Update Preferences.

Install the hotfix immediately

Servers configured for automatic daily updates should receive a patched build, but cPanel recommends applying this critical fix immediately rather than waiting for the next scheduled run:

/scripts/upcp --force

Alternatively, in WHM go to Home > cPanel > Upgrade to Latest Version, install the latest available update, and verify the resulting build again.

What to review after patching

The update closes the known vulnerability but cannot undo a prior compromise. If an affected server allowed customers to create parked or addon domains, review it for unexpected privileged changes:

  • recently created or modified files in root-owned and executable paths;
  • unfamiliar root SSH keys, administrator accounts, or sudoers entries;
  • unexpected services, cron jobs, systemd units, and startup scripts;
  • suspicious cPanel account activity and domain additions;
  • unexplained outbound connections or newly listening services.

If you find indicators of compromise, isolate the server, preserve evidence, rotate privileged credentials from a trusted system, and rebuild from known-good sources where appropriate.

What is CVE-2026-65643?+
It is a critical flaw in cPanel & WHM domain parking functionality. An authenticated cPanel account allowed to add parked or addon domains may create arbitrary server files, potentially leading to root code execution.
Are all cPanel versions affected?+
cPanel's 27 August 2026 advisory listed all supported versions as affected and supplied fixed builds for branches 110, 134, 136, 138, and WP Squared 138.1. Unsupported branches should be upgraded to a supported patched release.
How do I install the cPanel hotfix?+
Run /scripts/upcp --force as root, or use WHM > Home > cPanel > Upgrade to Latest Version. Verify the complete installed build afterward.
Does disabling parked and addon domains fix the vulnerability?+
No. Removing those feature permissions can temporarily reduce exposure, but only installing a patched cPanel build fixes the vulnerable code.

Next steps

Keeping a current cPanel license allows supported servers to receive security hotfixes through the normal update channel.

changelog
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
7 min read
changelog
CVE-2026-67401: the cPanel EmailTrack flaw that turns mail access into root
A SQL injection in cPanel's EmailTrack feature lets any account with mail privileges write files as root. Fixed builds, affected versions, and how to check your fleet.
7 min read
changelog
cPanel TSR-2026-09-08: prepare for the critical WHM patch
cPanel pre-announced a Targeted Security Release for 8 September 2026 fixing a critical cPanel & WHM vulnerability. Here is how to identify affected servers and apply the fix.
4 min read
changelog
cPanel TSR-2026-09-29: patch three WHM security vulnerabilities
cPanel TSR-2026-09-29 fixes two stored XSS flaws in WHM and a Multilang Adminbin authorization bypass that may permit command execution. Check your full build number and update now.
5 min read
changelog
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
7 min read
changelog
EasyApache 4 25.82: cPanel patches ea-libxml2, ea-nginx, ea-ruby27-ruby
EasyApache 4 build 25.82 patches eight libxml2 CVEs, two Ruby resolv CVEs, and bumps ea-nginx to 1.31.5. Here's what's affected and how to update.
5 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.