Permission to park a domain can hand over the entire server

cPanel patched a vulnerability in the domain parking functionality of cPanel and WHM on 27 August 2026. The flaw carries the number CVE-2026-65643. A logged-in cPanel user who is allowed to add parked domains or addon domains can create files anywhere on the server. Where that succeeds the code runs as root, and the attacker then controls every account, every website and every database on the machine.

All supported versions are affected. cPanel states that the fix is present in builds 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and WP2 11.138.1.7, or in a later version on the corresponding release branch.

What this means for you if you run a cPanel server

On a shared server the boundary between customers is the whole security model. A flaw that lets one account cross that boundary turns whatever happens with your least careful customer into everybody's problem. Our assessment is that this is the most uncomfortable class of vulnerability in shared hosting, because the attacker does not need to break in at all. An account can be bought, and a stolen password for a single customer is enough.

Who holds permission to park domains is therefore a question worth answering today. The right is handed out freely because it looks harmless and because customers ask for it. If you run a server where you do not know every account, treat the update as urgent rather than as maintenance.

Berigo recommends

  • Look up which build the server runs, and update to the fix on your own release branch.
  • Review which accounts are allowed to add parked domains and addon domains.
  • Look for files created outside the customers' own directories in recent weeks.
  • Require two-factor login on the accounts, so a stolen password is not enough to get in.
  • Agree with your provider who owns the update, if operations are outsourced.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch