Cpanel · Cpanel · CVE-2026-65643
**Name of the Vulnerable Software and Affected Versions**
cPanel & WHM versions prior to 11.110.0.141
cPanel & WHM versions prior to 11.134.0.53
cPanel & WHM versions prior to 11.136.0.37
cPanel & WHM versions prior to 11.138.0.2
WP Squared versions prior to 11.138.1.7
**Description**
An eval injection and arbitrary file write flaw exists in the domain parking and addon domain functionality. An authenticated user with permissions to manage these domains can create arbitrary files on the underlying server, leading to privilege escalation and remote code execution as root. This allows a low-privileged account holder to bypass hosting security boundaries and gain full control over the entire server, including all hosted accounts, databases, and configuration files.
**Recommendations**
Update cPanel & WHM to version 11.110.0.141 or later.
Update cPanel & WHM to version 11.134.0.53 or later.
Update cPanel & WHM to version 11.136.0.37 or later.
Update cPanel & WHM to version 11.138.0.2 or later.
Update WP Squared to version 11.138.1.7 or later.
As a temporary workaround, disable the Park Domain and Addon Domain features in the WHM Feature Manager for non-admin users.
Administrators can force an update by running the `/scripts/upcp --force` command.