CVE-2026-65643

Published Sep 1, 2026

Last updated 6 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-65643 is an arbitrary file creation flaw, also described as an "eval injection" vulnerability, found within the domain parking and addon domain features of cPanel & WHM. This vulnerability allows an authenticated cPanel account holder, who possesses the permissions to add parked or addon domains, to write arbitrary files to any location on the server. Successful exploitation of CVE-2026-65643 can lead to code execution as the root user, granting an attacker full control over the entire server, including all hosted accounts, websites, and databases. The flaw affects all supported versions of cPanel & WHM prior to the release of patches on August 27, 2026, following its discovery by cPanel support technician Devon Courtney.

Description
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Source
support@hackerone.com
NVD status
Analyzed
Products
cpanel

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-95

Social media

Hype score
Not currently trending
  1. GitHub - tc4dy/CVE-2026-65643-PoC-Toolkit: 🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, https://t.co/IsVo7WWsx3

    @akaclandestine

    8 Sept 2026

    3343 Impressions

    12 Retweets

    45 Likes

    26 Bookmarks

    0 Replies

    0 Quotes

  2. cPanel users: CVE-2026-65643 (CVSS 8.7) allows authenticated remote code execution as root in 11.138 and earlier. Review exposure and update. https://t.co/YGPNdY0Uv7 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/RsyIRRYuDb

    @ADKCyber

    2 Sept 2026

    29 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Security Alert: Critical cPanel & WHM Vulnerability – CVE-2026-65643 https://t.co/bSVqARR3eY

    @Rw_csirt

    1 Sept 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Patch Now | August 31, 2026 Bringing these patches to your attention. - cPanel (CVE-2026-65643) - Oracle WebLogic (CVE-2026-21962, CVSS 10.0) - Avada WordPress Theme (CVE-2026-18431, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/R87BUwfN5r

    @CERT_UG

    31 Aug 2026

    100 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Legacy exposure keeps paying off for attackers. cPanel CVE-2026-65643 turns domain parking into a root-co… cPanel patched CVE-2026-65643, a domain parking flaw that can let authenticated hosting use… 🔗 Read → https://t.co/9yS3iNYOdY

    @fynn_JourX

    31 Aug 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛑 cPanel CVE-2026-65643 turns domain parking into a root-control risk cPanel patched CVE-2026-65643, a domain parking flaw that can let authenticated hosting use… 🔗 Details → https://t.co/uoJl7ig5BO

    @lucasverdan

    31 Aug 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 cPanel zero-day (CVE-2026-65643): a low-privilege login can seize ROOT control of the entire server via domain parking. No phishing, no malware needed. Patch now if you run cPanel/WHM. Full breakdown 🔗 via Xpert4Cyber #cybersecurity #cpanel #zeroday #infosec https://t.c

    @Xpert4Cyber

    30 Aug 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. For defenders, cpanel cve-2026-65643 turns domain parking into a root-control… should move fast. cPanel patched CVE-2026-65643, a domain parking flaw that can let authenticated hosting use… 🔗 Details → https://t.co/1mKWR2BB2T

    @SocXAInvaders

    28 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. I discovered and reported CVE-2026-65643 Critical vulnerability in cPanel’s domain parking allowing a low level authenticated cPanel account to execute root commands. Thanks for @cPanel team for issuing an immediate patch for this https://t.co/nLU92mSTkZ #CVE #cPanel

    @the_rz1027

    28 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔐Secure the Stack | cPanel & Plesk Two recently disclosed vulnerabilities require attention from server administrators: • cPanel — CVE-2026-65643 • Plesk — CVE-2026-67394 Review your versions and apply available security updates. Details below👇 #SecureTheStack #

    @cplicensenet

    28 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. 🚨 cPanel'de Kritik Root Açığı CVE-2026-65643 kodlu açık, tek bir hosting müşterisinin sunucuda root yetkisiyle kod çalıştırmasına izin verebiliyor. Desteklenen tüm cPanel & WHM sürümleri etkileniyor. Güncelleme kritik. #CVE #SiberGüvenlik https://t.co/s

    @KubbeSiber

    28 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. cPanel-Fehler CVE-2026-65643: Root-Codeausführung über geparkte und Addon-Domains möglich: https://t.co/vMa65b7elo - #hacker #news #technology #technologie #it #informationstechnologie #hacking #computer #nerds #itsicherheit #itsecurity #itnews #cybercrime #cybersecurity #hack

    @mitchcasspari

    28 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. cPanel and Plesk both patched a root escalation on Aug 27. Same headline, opposite response. cPanel (CVE-2026-65643): an account that can add a parked or addon domain writes arbitrary files and runs code as root. Routine feature, every shared server. No mitigation. Patch. Plesk

    @stanislavdevops

    28 Aug 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations