CVE-2026-65643

cpanel: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CVE-2026-65643)

Beschreibung

Evaluationsinjektion in cPanel 11.138.0.0 und früher ermöglicht es authentifizierten Remote-Benutzern, beliebigen Code als Root auszuführen.

Metriken

Severity
high
PoC (öffentlich gemeldet)
8.8
Quelle: nvd-v3
57.7 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.9 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-01 02:07 UTC
CWE-95

Weakness-Klassen (CWE)

  • CWE-95Variant

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

    The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-09-04 20:30 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    • CPE Configuration: OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions up to (excluding) 11.110.0.141 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.112.0.0 up to (excluding) 11.134.0.53 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.136.0.0 up to (excluding) 11.136.0.37 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.138.0.0 up to (excluding) 11.138.0.2 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.138.1.0 up to (excluding) 11.138.1.7
    • Reference Type: HackerOne: https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Park-API-Vulnerability-August-27-2026 Types: Vendor Advisory
  2. CVE Modified2026-09-02 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-65643","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-65643","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. CVE Modified2026-09-01 13:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-65643","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • cpanel

    cpanel11.112.0.0 – 11.134.0.53

  • cpanel

    cpanel11.136.0.0 – 11.136.0.37

  • cpanel

    cpanel11.138.0.0 – 11.138.0.2

  • cpanel

    cpanel11.138.1.0 – 11.138.1.7

  • cpanel

    cpanel11.110.0.141

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-65643