Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
- ID
- 18987
- Status
- summarized
- Published
- 28 Aug 2026, 5:45 PM
- Fetched
- 28 Aug 2026, 7:29 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 28 Aug 2026, 7:33 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
cPanel patched CVE-2026-65643, a critical flaw in domain parking and addon domain functionality that lets any authenticated hosting customer who can add parked/addon domains create arbitrary files and escalate to root, giving full server control. Patched builds are 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP Squared); servers with automatic daily updates get the fix automatically, or admins can run /scripts/upcp --force.
Why it matters
If you run or rent on a cPanel/WHM shared hosting server, a single tenant on that box can now root the entire machine—so verify your provider has applied the patch or, if you administer the box, run /scripts/upcp --force immediately and confirm the build number under Server Configuration > Update Preferences. End-of-life cPanel versions cannot receive the fix and must be upgraded to a supported branch.
Discussion angle
How many Malaysian startups and agencies still ship on cPanel shared hosting, and what's the realistic migration path when a single co-tenant can now own the whole server?