cPanel, trivial escalation to root exploit CVE-2026-65643

AnthonySmithAnthonySmith AdministratorProviderOG

https://blog.kalfaoglu.net/posts/2026-09-03-cpanel-cve-2026-65643-domain-parking-en/

CVE-2026-65643: Any cPanel User with Parked Domains Can Get Root, Patch Now

On August 27, 2026, cPanel pushed an unscheduled security update and sent a customer notification that most people probably skimmed past. They shouldn’t have.

The flaw, assigned CVE-2026-65643, lets any authenticated cPanel account that has permission to add parked or addon domains create arbitrary files on the underlying server which in practice means full root-level code execution.

That’s not a privilege escalation hidden behind multiple hoops. That’s a regular shared hosting customer owning the machine.

TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/

Comments

Sign In or Register to comment.