started · updated
cPanel vulnerability allows attackers to seize full server control
A critical vulnerability, tracked as CVE-2026-65643, has been identified in the cPanel and WHM web hosting control panel software. The flaw resides in the domain parking functionality and could allow a low-privileged, authenticated user to gain root-level control of an entire server.
By exploiting the bug, an attacker with permission to add parked or addon domains can create arbitrary files anywhere on the underlying server. Successful exploitation leads to code execution as the root user, which poses a significant risk to shared hosting environments. In such multi-tenant infrastructures, a single compromised account could expose every other website, database, and email account hosted on the same machine.
As a precautionary measure, some hosting providers have temporarily disabled the ability to create new subdomains, addon domains, and parked domains on affected servers. This restriction only impacts the creation of new domains; existing subdomains and parked domains remain functional. Infrastructure teams are currently working toward a resolution to restore these features safely.