• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65643: authenticated code injection in WebPros cPanel

Remote authenticated users can execute arbitrary code as root on cPanel servers, allowing full system compromise. CVE-2026-65643 is an eval injection in cPanel 11.x that affects releases before the listed fixed builds; affected ranges include versions before 11.110.0.141 and several later 11.x ranges fixed at 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7. Exploitation requires an account on the cPanel instance (low privileged authenticated access) and network access to the service.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00875
CWE
CWE-95
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — public exploit code exists, so vulnerable cPanel servers with any user accounts reachable over the network should be patched or isolated immediately.

What is CVE-2026-65643?

Remote authenticated users can execute arbitrary code as root on cPanel servers, allowing full system compromise. CVE-2026-65643 is an eval injection in cPanel 11.x that affects releases before the listed fixed builds; affected ranges include versions before 11.110.0.141 and several later 11.x ranges fixed at 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7. Exploitation requires an account on the cPanel instance (low privileged authenticated access) and network access to the service.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of WebPros cPanel are affected?

BRANCHAFFECTEDFIXED
11.xbefore 11.110.0.14111.110.0.141
11.x11.112.0.0 – before 11.134.0.5311.134.0.53
11.x11.136.0.0 – before 11.136.0.3711.136.0.37
11.x11.138.0.0 – before 11.138.0.211.138.0.2
11.x11.138.1.0 – before 11.138.1.711.138.1.7

Is CVE-2026-65643 being exploited?

Public exploit code is available.

How to fix CVE-2026-65643

  1. Upgrade cPanel to one of the fixed builds: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or 11.138.1.7 as appropriate for your branch.
  2. Restrict access to cPanel interfaces to trusted networks or VPNs while you patch.
  3. Review and remove unneeded or suspicious user accounts and rotate credentials for remaining accounts.
  4. Monitor system logs and command history for signs of unauthorized root activity and isolate any compromised hosts.

Frequently asked questions

Is CVE-2026-65643 being actively exploited?

Public exploit code is available for CVE-2026-65643, which increases the risk of active exploitation against cPanel instances.

Which cPanel versions are affected by CVE-2026-65643?

cPanel 11.x releases are affected in multiple ranges: builds before 11.110.0.141 and several later 11.x ranges fixed at 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 are listed as patched.

Is there a patch for CVE-2026-65643?

Yes; WebPros released fixes for cPanel in the builds 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 depending on branch.

Does CVE-2026-65643 require authentication?

Yes; exploitation requires an authenticated account on the cPanel instance (low-privileged credentials) but no user interaction beyond that.

References