Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


In this Discussion

New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Tony40Tony40 Member

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.

The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.

cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server.

"Successful exploitation leads to code execution as the root user, giving an attacker full control of the server," cPanel said in a notification to customers. ...

https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html

Thanked by 1JasonM

Comments

  • JasonMJasonM Member

    every new day cPanel has a new vulnerability.
    guess how many vulnerabilities other not-so-maintained panels would have!

    Thanked by 2Tony40 COLBYLICIOUS
  • LeviLevi Veteran

    Hard times for cPanel perl code maintainers.

    Thanked by 1COLBYLICIOUS
Sign In or Register to comment.