Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ali Mustafa

#31707of 56,333
8.8Total CVSS
Vulnerabilities · 1
PT-2026-82649
8.8
2026-08-27
Cpanel · Cpanel · CVE-2026-65643
**Name of the Vulnerable Software and Affected Versions** cPanel & WHM versions prior to 11.110.0.141 cPanel & WHM versions prior to 11.134.0.53 cPanel & WHM versions prior to 11.136.0.37 cPanel & WHM versions prior to 11.138.0.2 WP Squared versions prior to 11.138.1.7 **Description** An eval injection and arbitrary file write flaw exists in the domain parking and addon domain functionality. An authenticated user with permissions to manage these domains can create arbitrary files on the underlying server, leading to privilege escalation and remote code execution as root. This allows a low-privileged account holder to bypass hosting security boundaries and gain full control over the entire server, including all hosted accounts, databases, and configuration files. **Recommendations** Update cPanel & WHM to version 11.110.0.141 or later. Update cPanel & WHM to version 11.134.0.53 or later. Update cPanel & WHM to version 11.136.0.37 or later. Update cPanel & WHM to version 11.138.0.2 or later. Update WP Squared to version 11.138.1.7 or later. As a temporary workaround, disable the Park Domain and Addon Domain features in the WHM Feature Manager for non-admin users. Administrators can force an update by running the `/scripts/upcp --force` command.