CVE-2026-65643: Cpanel Cpanel vulnerability
Published Sep 1, 2026
·Updated
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
Affected Software
1 affected component
Cpanel Cpanel<=11.138.0.0
Event History
Sep 1, 2026
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be remotely authenticated to exploit the vulnerability. The affected versions allow such users to execute arbitrary code as root.
2
Which cPanel versions are affected?
cPanel 11.138.0.0 and earlier are affected.