
cPanel CVE-2026-65643 Grants Root via Addon Domains in Shared Hosting
A single cPanel account with addon domain rights can now achieve root on shared servers. The flaw continues a 2026 pattern of cPanel and plugin privilege escalations already tracked by CISA. No mitigations or detection methods were released with the patch.
The vulnerability affects all supported cPanel & WHM branches including 11.110, 11.134, 11.136 and 11.138. An account with standard domain parking rights can create files outside its chroot, directly yielding root. cPanel lists fixed builds but supplies no CVSS score, no interim mitigation steps, and no detection commands. The CVE record remains unpublished while earlier July flaws already appear in the database.
Procurement and incident patterns show repeated cPanel weaknesses this year. CISA's KEV already lists three related entries: CVE-2026-48172 and CVE-2026-54420 in the LiteSpeed plugin plus the April authentication bypass CVE-2026-41940 used in ransomware. The current flaw follows the same vector of insufficient path validation when customers manage addon domains, yet cPanel again omitted Team User sub-account scope and offered no log-grep guidance.
Shared hosting economics amplify the impact. One compromised or malicious customer account can now seize the entire physical host, exposing every tenant on servers that commonly run hundreds of sites. Automatic daily updates reach only configured systems; end-of-life branches require full version jumps first. Absence of compromise verification tools leaves operators without post-patch assurance.
Operators must force /scripts/upcp immediately and audit recent domain additions. Future releases should publish CVSS and detection artifacts at disclosure rather than weeks later.
SENTINEL: Within 45 days of public patch release, at least one ransomware group will publish a working exploit targeting unpatched 11.110 and 11.134 builds.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html)
- [2]Supporting Source(https://www.cpanel.net)
- [3]Supporting Source(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)