High SEVERITY — Vulnerability

CVE-2026-65643 — Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Platform
cPanel & WHM
CVE Record
CVE-2026-65643
CVSS Score
8.7/10
Published
01 September 2026
Views
21
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Assessment

  • CVE: CVE-2026-65643
  • CVSS base score: 8.7
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched
cpanel *

cPanel & WHM — Related Advisories

VIEW ALL →