Executive brief
cPanel is a web hosting control panel used by administrators to manage servers and customer accounts. An authenticated attacker can inject arbitrary code through the Park API that executes with root privileges, potentially giving an attacker complete control over the hosting server and all customer data.
Technical details
The vulnerability is an eval injection flaw in the Park API component of cPanel versions 11.138.0.0 and earlier. The vulnerability requires authentication but allows remote attackers to inject and execute arbitrary code with root-level privileges. An authenticated attacker can exploit this to achieve complete code execution on the affected system, compromising the entire server infrastructure. A patch is available from cPanel.
Affected products
- cPanel cPanel 11.138.0.0 and earlier
Timeline
- 2026-09-01: disclosed