Eval Injection Vulnerability in cPanel by cPanel, Inc.
CVE-2026-65643
Key Information:
Badges
What is CVE-2026-65643?
CVE-2026-65643 is a significant vulnerability found in cPanel, a widely used web hosting control panel developed by cPanel, Inc. This software streamlines the management of web hosting accounts for both users and administrators, allowing for tasks such as website management, email handling, and database administration. The vulnerability stems from an eval injection flaw present in versions 11.138.0.0 and earlier, which enables remote authenticated users to execute arbitrary code with root privileges. This weakness can be detrimental to organizations, as it potentially allows malicious actors to manipulate server environments, gain unauthorized access to sensitive data, and disrupt services.
With root access, an attacker can deploy various malicious actions, such as installing malware, modifying configurations, or targeting other systems within the network. This highlights the importance of addressing vulnerabilities like CVE-2026-65643 to maintain the security and integrity of impacted systems and to avoid potential operational and reputational damage.
Potential impact of CVE-2026-65643
-
Remote Code Execution: The ability for authenticated users to execute arbitrary code means that attackers can take full control of the affected servers, leading to severe operational disruptions and unauthorized access to critical data.
-
Data Breaches: Exploiting this vulnerability could expose sensitive information, putting both user data and organizational assets at risk. This can lead to significant financial losses, reputational damage, and legal repercussions.
-
Service Disruption: Malicious exploitation of this flaw can result in the unavailability of services provided through cPanel, disrupting not only the organization’s operations but also impacting customers relying on those services.
Affected Version(s)
cPanel 0 < 11.110.0.141
cPanel 11.112.0.0 < 11.134.0.53
cPanel 11.136.0.0 < 11.136.0.37
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server - SwapUpdate
Swati KhandelwalAug 28, 2026Vulnerability / Web Security
2 days ago
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel patches CVE-2026-65643, a critical flaw that lets authenticated accounts with domain controls execute code as root.
4 days ago
References
CVSS V4
Timeline
- 📈
Vulnerability started trending
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability Reserved
