Junglewise Threat Intelligence

CVE-2026-65643: cPanel eval injection in Park API

CVE-2026-65643 · Severity: high · CVSS 8.8 · Published 2026-09-01

Executive brief

cPanel is a web hosting control panel used by administrators to manage servers and customer accounts. An authenticated attacker can inject arbitrary code through the Park API that executes with root privileges, potentially giving an attacker complete control over the hosting server and all customer data.

Technical details

The vulnerability is an eval injection flaw in the Park API component of cPanel versions 11.138.0.0 and earlier. The vulnerability requires authentication but allows remote attackers to inject and execute arbitrary code with root-level privileges. An authenticated attacker can exploit this to achieve complete code execution on the affected system, compromising the entire server infrastructure. A patch is available from cPanel.

Affected products

  • cPanel cPanel 11.138.0.0 and earlier

Timeline

  • 2026-09-01: disclosed

References