Full Report
WebPros security advisory (AV26-861)
Analysis Summary
# Vulnerability: Improper Access Control in cPanel Domain Parking
## CVE Details
- **CVE ID:** CVE-2026-65643
- **CVSS Score:** Not explicitly listed in source (Typically High for unauthorized domain control)
- **CWE:** CWE-284 (Improper Access Control) / CWE-285 (Improper Authorization)
## Affected Systems
- **Products:** cPanel & WebHost Manager (WHM)
- **Versions:**
- Prior to 11.110.0.141
- Prior to 11.134.0.53
- Prior to 11.136.0.37
- Prior to 11.138.0.2
- Prior to WP2: 11.138.1.7
- **Configurations:** Systems utilizing cPanel’s "Domain Parking" (Aliases) functionality.
## Vulnerability Description
A vulnerability exists in the Domain Parking functionality of cPanel. While technical specifics are constrained by the vendor advisory, the flaw involves a failure to properly validate or restrict access when a user attempts to park/alias a domain. This could potentially allow an attacker to associate unauthorized domains with their account or bypass established administrative restrictions regarding domain ownership verification.
## Exploitation
- **Status:** Not reported as exploited in the wild (as of August 28, 2026).
- **Complexity:** Medium
- **Attack Vector:** Network (Web Interface)
## Impact
- **Confidentiality:** Low
- **Integrity:** High (Potential unauthorized modification of domain mappings)
- **Availability:** Low (Potential service disruption for legitimate domain owners)
## Remediation
### Patches
WebPros has released the following patched versions. Administrators should update to the relevant branch:
- **cPanel & WHM 11.110.x:** Update to 11.110.0.141 or later.
- **cPanel & WHM 11.134.x:** Update to 11.134.0.53 or later.
- **cPanel & WHM 11.136.x:** Update to 11.136.0.37 or later.
- **cPanel & WHM 11.138.x:** Update to 11.138.0.2 or later.
- **WP2 Branch:** Update to 11.138.1.7 or later.
### Workarounds
No specific functional workarounds have been provided. Disabling user-level domain parking (Aliases) in the Feature Manager may mitigate risk until patches are applied.
## Detection
- **Indicators of Compromise:** Review cPanel access logs and account activity logs for unusual domain parking or alias creation requests, specifically focusing on domains not owned by the requesting user.
- **Detection methods:** Audit current parked domains via WHM to ensure all aliases correlate with authorized user accounts.
## References
- **Vendor Advisory:** hxxps[://]support[.]cpanel[.]net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Vulnerability-in-cPanel-s-Domain-Parking-Functionality-August-27-2026
- **cPanel Security Center:** hxxps[://]support[.]cpanel[.]net/hc/en-us/sections/360007088193-Security
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/webpros-security-advisory-av26-861