CVE-2026-65643: High severity Cpanel Cpanel vulnerability
Published Sep 1, 2026
·Updated
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Affected Software
6 affected components
Cpanel Cpanel<=11.138.0.0
Cpanel Cpanel<110.0.141
Cpanel Cpanel>=112.0.0<134.0.53
Cpanel Cpanel>=136.0.0<136.0.37
Cpanel Cpanel>=138.0.0<138.0.2
Cpanel Cpanel>=138.1.0<138.1.7
Event History
Sep 1, 2026
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be remotely authenticated to exploit the vulnerability. The affected versions allow such users to execute arbitrary code as root.
2
Which cPanel versions are affected?
cPanel 11.138.0.0 and earlier are affected.