PT-2026-82649 · Cpanel · Cpanel+1

·

CVE-2026-65643

·

Published

2026-08-27

·

Updated

2026-09-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cPanel & WHM versions prior to 11.110.0.141 cPanel & WHM versions prior to 11.134.0.53 cPanel & WHM versions prior to 11.136.0.37 cPanel & WHM versions prior to 11.138.0.2 WP Squared versions prior to 11.138.1.7
Description An eval injection and arbitrary file write flaw exists in the domain parking and addon domain functionality. An authenticated user with permissions to manage these domains can create arbitrary files on the underlying server, leading to privilege escalation and remote code execution as root. This allows a low-privileged account holder to bypass hosting security boundaries and gain full control over the entire server, including all hosted accounts, databases, and configuration files.
Recommendations Update cPanel & WHM to version 11.110.0.141 or later. Update cPanel & WHM to version 11.134.0.53 or later. Update cPanel & WHM to version 11.136.0.37 or later. Update cPanel & WHM to version 11.138.0.2 or later. Update WP Squared to version 11.138.1.7 or later. As a temporary workaround, disable the Park Domain and Addon Domain features in the WHM Feature Manager for non-admin users. Administrators can force an update by running the /scripts/upcp --force command.

Fix

LPE

RCE

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65643

Affected Products

Whm
Cpanel