CVE-2026-65643CWE-95

CVE-2026-65643

High · published September 1, 2026

CVSS v3.1
8.8
EPSS
1%
Percentile
57.5
In the wild
Unconfirmed
What it is

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00904 · 57.5th percentile
Weakness
CWE-95 · Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Published
2026-09-01T07:16Z
Affected products (5)
ProductVersionsFixed in
cpanel/cpanel< 11.110.0.14111.110.0.141
cpanel/cpanel≥ 11.112.0.0, < 11.134.0.5311.134.0.53
cpanel/cpanel≥ 11.136.0.0, < 11.136.0.3711.136.0.37
cpanel/cpanel≥ 11.138.0.0, < 11.138.0.211.138.0.2
cpanel/cpanel≥ 11.138.1.0, < 11.138.1.711.138.1.7
References (1)
EPSS history
Timeline
  • 02 SEP 03:38Z
    EPSS moved — → 1%
    epss
  • 01 SEP 02:07Z
    Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root
    cvelistv5