Vulnerabilities
1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65643 | Authenticated eval injection in cPanel enables root code execution cPanel 11.138.0.0 and earlier contains an eval injection flaw (CWE-95) in which attacker-controlled input reaches dynamic code evaluation without proper neutralization. A remote attacker holding any authenticated account on a cPanel server, such as an ordinary hosting customer, can trigger the flaw with crafted input and no user interaction. Successful exploitation yields arbitrary code execution as root, meaning a single low-privilege tenant can compromise the entire server and every site hosted on it. All deployments running version 11.138.0.0 or earlier are affected, which at disclosure covers essentially all active cPanel servers given that this was the current release. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not in CISA KEV and EPSS assigns only a 0.9% probability of exploitation within 30 days. Do: Upgrade cPanel/WHM to a fixed release above 11.138.0.0 published under WebPros advisory AV26-861, prioritizing multi-tenant shared servers where any customer account can reach the vulnerable code. Until patched, restrict shell and feature access for untrusted accounts and review authentication logs and unexpected root-owned processes. No workaround is documented in the available data, so updating is the primary action. | 8.7 | <1% |
| massroughly hundreds of thousands of cPanel/WHM servers (millions of hosted sites on multi-tenant shared hosting) |