cPanel, trivial escalation to root exploit CVE-2026-65643
AnthonySmith
AdministratorProviderOG 




https://blog.kalfaoglu.net/posts/2026-09-03-cpanel-cve-2026-65643-domain-parking-en/
CVE-2026-65643: Any cPanel User with Parked Domains Can Get Root, Patch Now
On August 27, 2026, cPanel pushed an unscheduled security update and sent a customer notification that most people probably skimmed past. They shouldn’t have.
The flaw, assigned CVE-2026-65643, lets any authenticated cPanel account that has permission to add parked or addon domains create arbitrary files on the underlying server which in practice means full root-level code execution.
That’s not a privilege escalation hidden behind multiple hoops. That’s a regular shared hosting customer owning the machine.
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/
Comments
New one today too: https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026
But I didn't even know anyone really used that CSF function, and it's not really "cPanel" itself.
I'm mildly annoyed at all of the updates, but they really are on the ball with getting them out fast now.
Do everything as though everyone you’ll ever know is watching.
I used to, took me a minute to remember what it was lol
TierHive - Hourly VPS - NAT Native - /24 per customer - DE, UK, SG, CA, USA x4, FR x2, AU, PL, NL, JP
FREE tokens on sign up, try before you buy. | Static Hosting Free for life: https://tierhive.com/static-hosting/