Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker News by The Hacker News
August 28, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalAug 28, 2026Vulnerability / Web Security

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.

The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.

cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server.

“Successful exploitation leads to code execution as the root user, giving an attacker full control of the server,” cPanel said in a notification to customers.

cPanel has released the following patched versions –

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • 11.138.1.7 or later (WP Squared)

The notification names WP Squared in its patched list and does not mention DNSOnly.

cPanel patched three separate flaws in July, and the fixed builds named in those advisories included the 11.118 and 11.126 branches. The August 27 list covers the 110, 134, 136, and 138 branches, and the company has not said whether 11.118 and 11.126 remain supported.

cPanel said in its July advisory about the Exim flaw that it may allow privilege escalation from Team User sub-accounts. The August 27 notification does not specify whether a Team User sub-account with permission to the parked and addon domains is in scope.

Servers configured for automatic daily updates receive the patched build automatically, according to the advisory published on August 27.

Administrators can apply it immediately by logging in to the server as root and running /scripts/upcp –force. The update can also be installed from WHM under Home > cPanel > Upgrade to Latest Version, and the installed build can then be verified under Server Configuration > Update Preferences.

Servers running an end-of-life version have to upgrade to a supported version to receive the fix.

The customer notification carries no CVSS score, and The Hacker News confirmed via the CVE Program’s record store on August 28, 2026, that no record has been published for CVE-2026-65643. Records for CVE-2026-58048 and CVE-2026-58047, two cPanel flaws disclosed on July 31, were both present at the time of the check.

cPanel has not said whether the flaw has been exploited, and it is absent from the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog as of the version released on August 27, 2026. The catalog already carries two flaws in a cPanel plugin.

CISA added CVE-2026-48172, a privilege escalation issue in the LiteSpeed cPanel plugin, on May 26, 2026, and noted that it can be exploited by any cPanel user account to execute arbitrary scripts with root privileges.

It added CVE-2026-54420, a symlink-following flaw in the same plugin, on June 15, 2026, for shared hosting servers running CloudLinux or CageFS where a user has FTP or web shell access.

The catalog also lists CVE-2026-41940, the authentication bypass patched in April, with known use in ransomware campaigns.

The customer notification provides no interim mitigation and no way to verify whether a server has already been compromised.

cPanel carried a command to grep the Apache error log for signs of exploitation in its Phusion Passenger advisory, published on August 14, 2026.

cPanel said that the issue does not affect default installations and applies only to servers where an affected Passenger package has been installed.

Plesk, which WebPros develops alongside cPanel, updated its own advisory for the same flaw on August 14, 2026, with a five-item checklist for spotting a prior compromise that begins with unexpected entries in /etc/ld.so.preload.

“Patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done,” Plesk said.

Phusion, which develops Passenger, shipped a fix in Passenger 6.2.0  on August 18, 2026, for a Watchdog API flaw that does not have a CVE identifier.

“We have seen exploitation of this vulnerability in the wild at a shared hosting provider,” Phusion said.



Source link

The Hacker News

The Hacker News

Next Post

Inside Meta’s Push to Put Robots to Work in Data Centers

Recommended.

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

November 18, 2025
Police intercept evidence from Sky ECC cryptophone network ‘unreliable’, Antwerp court told | Computer Weekly

Police intercept evidence from Sky ECC cryptophone network ‘unreliable’, Antwerp court told | Computer Weekly

February 3, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio