# cPanel patches flaw that could give hosting accounts root access

_Wednesday, August 26, 2026 at 8:00 PM EDT · Security · Latest · Tier 1 — Major_

![cPanel patches flaw that could give hosting accounts root access — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtKp2lGcxPfp8ymA88FIBXB0Bn9fcUSaU_UIl1pfAjDSC2usRwUE73vhQEeP6jar9U9k10yotgyYl_tIk6dQA-MFIr2bJ3LN_azGt9kDU6hpW448HgmBuJbc6TWSo1vfpmhoK0J3_5rhF6VIpWd7NYf0G1YSYHdqKubWgQwa1yU6KRAL-bnDGd8HmCmPk/s1700-e365/cpanel-root.jpg)

cPanel has released patches for CVE-2026-65643, a critical flaw in domain parking and addon-domain functions affecting all supported cPanel and WHM versions.

The company said an authenticated account allowed to add those domains could create arbitrary server files, leading to code execution as root. Fixed builds are available for several release branches, and servers using automatic daily updates receive them automatically. cPanel has not said the flaw has been exploited, and it was not listed in CISA's Known Exploited Vulnerabilities catalog as of August 27.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html)

---
Canonical: https://techandbusiness.org/newswire/G67cBL4DB5Yj-ODiBTwvHR
Retrieved: 2026-08-28T12:43:08.309Z
Publisher: Tech & Business (techandbusiness.org)
