DEV Community

Cover image for cPanel Patches Root Escalation Flaw in Domain Management
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

cPanel Patches Root Escalation Flaw in Domain Management

Summary

cPanel fixed a vulnerability (CVE-2026-65643) that allows authenticated users to gain root access by exploiting domain parking features. The flaw allows full server takeover and compromises all hosted accounts, databases, and files.

Take Action:

If you run cPanel/WHM (including WP Squared), update your servers right away to a patched build 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 or later using the upcp script or the WHM interface. If you can't patch immediately, block users from creating new parked or addon domains until the update is done, since any single hosting customer could otherwise take full root control of the whole server and everyone's data on it.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)