CVE-2026-65643
Received Received - Intake

Eval Injection in cPanel Prior to 11.138.0.0

Vulnerability report for CVE-2026-65643, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: HackerOne

Description

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
cpanel cpanel 11.138.0.0
cpanel cpanel From 11.110.0.141 (inc)
cpanel cpanel From 11.134.0.53 (inc)
cpanel cpanel From 11.136.0.37 (inc)
cpanel cpanel From 11.138.0.2 (inc)
cpanel cpanel From 11.138.1.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an eval injection flaw in cPanel versions 11.138.0.0 and earlier. It allows remote authenticated users to execute arbitrary code with root privileges by exploiting the Domain Parking functionality. Attackers can create arbitrary files on the server, leading to full system compromise.

Impact Analysis

If exploited, this vulnerability allows attackers to gain full control over the server as the root user. This means they can access all accounts, websites, and databases hosted on the server, leading to data theft, defacement, or further attacks.

Compliance Impact

This vulnerability can severely impact compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires protecting personal data, while HIPAA mandates securing protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update cPanel/WHM to the latest patched versions: 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, or WP2: 11.138.1.7 or later. This addresses the vulnerability and prevents potential code execution as root.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65643. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart