CVE-2026-65643 is a critical cPanel & WHM vulnerability that can let an authenticated hosting user escalate to code execution as root. The attacker needs a cPanel account allowed to add parked or addon domains; this is not unauthenticated Internet RCE. On a shared server, however, one compromised account can put every website, database, and secret on the machine at risk.
Do this now: update cPanel to a fixed build, verify the version actually running, and investigate the server if an unknown or compromised account could manage domains before the update.
| Fact | Confirmed value |
|---|---|
| ID | CVE-2026-65643 |
| Required access | Authenticated cPanel account able to add parked or addon domains |
| Impact | Arbitrary file creation and code execution as root |
| Potential scope | Every account, site, and database on the affected server |
| Fix | Install a patched build or later |
Why the impact is severe
cPanel says the vulnerable domain-parking functionality can let an eligible account holder create arbitrary files. Once that operation crosses the boundary between a tenant and the operating system, it can become root code execution. Root can read or change other customers' files, secrets and services, making this especially serious for resellers and agencies that consolidate many clients.












