Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Summary
cPanel has released patches for a critical security vulnerability in its cPanel and WebHost Manager (WHM) software. This flaw could allow a hosting customer to gain root control of an entire server by exploiting domain parking and addon domain functionalities. The vulnerability is assigned the CVE identifier CVE-2026-65643 and affects all supported versions.
IFF Assessment
This vulnerability allows a low-privileged user to gain root access, posing a significant threat to server security and data integrity.
Severity
This is a critical vulnerability with a high attack vector and significant impact. An attacker can achieve remote code execution with root privileges, allowing full compromise of the server.
Defender Context
This critical vulnerability in cPanel/WHM could lead to complete server compromise, allowing attackers to take root control. Defenders must prioritize patching this flaw immediately to prevent potential data breaches and service disruptions. This highlights the importance of timely patching for widely used hosting control panels.