cPanel Fixes Domain Parking Flaw That Could Give Attackers Root Access

cPanel has released security updates to fix a serious vulnerability in its domain parking and addon domain functionality that could allow an authenticated hosting user to gain full control of a server.

The issue, tracked as CVE-2026-65643, affects all supported versions of cPanel & WHM that have not yet received the relevant security patch.

What is the vulnerability?

The flaw can be exploited by an authenticated cPanel account holder who has permission to add parked or addon domains.

A vulnerable server could allow that user to create arbitrary files on the system. If successfully exploited, the issue can lead to code execution with root privileges, the highest level of access on a Linux server.

Root access would give an attacker control over the entire server, potentially exposing every hosted account, website, database and file stored on it.

The risk is particularly important for shared hosting providers, where many customers may have separate cPanel accounts on the same server.

Which cPanel versions are patched?

Administrators should make sure their servers are running at least the following versions:

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • WP Squared (WP2): 11.138.1.7 or later

Because successful exploitation can result in complete server compromise, hosting providers and server administrators should install the available cPanel updates as soon as possible.

Updates can be applied through WHM → Home → cPanel → Upgrade to Latest Version or from a root shell using the command: /usr/local/cpanel/scripts/upcp –force

Server operators should also confirm that their installed cPanel version matches or exceeds the patched release for their current branch.