---
id: CVE-2026-65643
title: >-
  Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated
  users to execute arbitrary code as root.
summary: >-
  Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated
  users to execute arbitrary code as root.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-95
vendor: cpanel
product: cpanel
affected:
  - cpanel < 110.0.141
  - 'cpanel >= 112.0.0, < 134.0.53'
  - 'cpanel >= 136.0.0, < 136.0.37'
  - 'cpanel >= 138.0.0, < 138.0.2'
  - 'cpanel >= 138.1.0, < 138.1.7'
patched:
  - cpanel 138.1.7
published: '2026-09-01'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T15:09:53.750'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65643'
references:
  - url: >-
      https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Park-API-Vulnerability-August-27-2026
    label: support@hackerone.com
tags:
  - nvd
  - exploit-available
epss: 0.00904
epssPercentile: 0.58283
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/tc4dy/CVE-2026-65643-PoC-Toolkit'
    - 'https://github.com/HORKimhab/CVE-2026-65643'
  checkedAt: '2026-09-23T07:14:35.660Z'
exploitAvailable: true
ingestedAt: '2026-09-05T19:43:56.479Z'
---

## Overview

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

## Affected

- `cpanel < 110.0.141`
- `cpanel >= 112.0.0, < 134.0.53`
- `cpanel >= 136.0.0, < 136.0.37`
- `cpanel >= 138.0.0, < 138.0.2`
- `cpanel >= 138.1.0, < 138.1.7`

## Remediation

Upgrade past the affected range:

- `cpanel 138.1.7`
