Emergency server help: get in touch

What changed in cPanel 138: Meridian, Ask AI, Nova, MCP and domain rename

An operations-focused summary of the cPanel 138 release from July 2026, covering the opt-in Meridian interface, the Ask AI assistant, the Nova site builder, MCP access for AI clients, the Node.js Toolkit, in-place domain renaming and the bundled component versions.

Published Updated 6 min read

cPanel 138 landed on the RELEASE tier in July 2026 and is the version new installs receive today. Where 136 removed and consolidated, 138 adds: a new interface, an AI assistant, an AI site builder, a protocol for letting external AI agents act on accounts, a container-based Node.js toolkit, and a long-requested domain rename. Most of these are opt-in, which is the right default, but each has implications for support, security and resource use that a hosting provider should decide on deliberately rather than discover from a customer ticket.

Short answer: cPanel 138 adds the opt-in Meridian interface, an Ask AI assistant, the Nova AI site builder, Model Context Protocol access that lets external AI agents act on accounts through scoped tokens, a Podman-based Node.js Toolkit and in-place renaming of primary and addon domains. It ships PHP 8.4, Exim 4.100, Dovecot 2.4 and Roundcube 1.6.19, requires Ubuntu 24.04 or AlmaLinux and CloudLinux 8 to 10, and every AI feature is controlled through feature lists and tweak settings that should be set deliberately.

Meridian, Ask AI and Nova

Meridian is a redesigned cPanel interface organised around six hubs instead of the Jupiter icon grid. It is off by default and can be enabled per server, per reseller or per account. The underlying functions are the same, and the UAPI and WHM API are unchanged, so nothing in provisioning breaks. What does change is your documentation and screenshots. If you enable it fleet-wide, update your knowledge base first; if you leave it to customers, expect tickets from users who turned it on and cannot find the File Manager. The enable and disable guide has the settings and the feature-list entries.

“Ask AI” is an assistant inside cPanel and WHM that answers questions about the account and can perform a whitelisted set of actions with confirmation. It is read-only unless you allow the approved actions, and it is a feature-list item, so you control who sees it. Two things to decide: whether account data being sent to the vendor’s AI service is acceptable under your terms of service and your customers’ expectations, and whether support staff want customers acting on AI advice before opening a ticket. Many providers enable it for resellers and leave it off for end users initially.

Nova is an AI site builder that replaces the deprecated Site Publisher and sits alongside Sitejet. It generates sites into the account’s document root, so it consumes disk and PHP resources like any other site; nothing unusual there, but it does make it easier for a customer to create a dozen throwaway sites in an afternoon.

MCP: authorising AI clients against cPanel

138 adds Model Context Protocol support, which lets an external AI client (a desktop assistant, an agent framework, an IDE plugin) connect to a cPanel account and call functions through a scoped authorisation. Authorisation is granted through a WHM widget, produces a token with an explicit permission scope, and is revocable. From a security standpoint it is another API token pathway, and it should be governed the same way: know which accounts have authorised which clients, review the list, and revoke on staff or customer changes.

Our MCP access guide shows how to audit what an authorised agent can actually do. If you have no need for it, disable the feature at the server level and revisit later.

AI-Native Node.js Toolkit

The Node.js Toolkit runs applications in Podman containers per account and supports deploying an application to a subdomain in a few clicks. It replaces the Passenger-based Application Manager for new deployments. Operationally, Podman means container images on disk and container processes that do not look like ordinary PHP workers in top; CloudLinux LVE limits apply to them but your resource-usage scripts may need updating. Check podman ps --all as root to see what is running server-wide. The deployment tutorial covers the customer side.

In-place domain rename

A primary or addon domain can now be renamed without recreating the account or the addon. The rename updates the vhost, DNS zone, mail configuration and document root references. It does not update the content of the site, so a WordPress install still needs its siteurl and home options changed and a search-and-replace on the database. It also does not carry certificates; AutoSSL issues a new one for the new name on its next run. Test it on a low-value domain before offering it to customers, and read renaming a domain in place for the sequence.

Component versions and operating system requirements

138 ships with PHP 8.4.25 for cPanel’s internal use, Exim 4.100.1, Dovecot 2.4.5 and Roundcube 1.6.19. Exim 4.100 includes the June 2026 security fixes; the Exim changes guide covers what admins need to know. EasyApache 4 offers PHP 8.2 through 8.5 with 8.4 as the mainstream default. AWStats, Webalizer and Analog are still present in 138 but are scheduled for removal in 140 once GoAccess is integrated; see replacing AWStats with GoAccess to get ahead of it.

138 requires Ubuntu 24.04; 22.04 is not supported. On the RHEL family it supports AlmaLinux 8, 9 (9.5 or later) and 10, and CloudLinux 8, 9 and 10. Rocky Linux was dropped in 134 and remains unsupported. If you are still on 134 LTS and planning the jump, the OS check is the first gate.

Security builds within 138

138 was current for the August and September root-escalation fixes: 138.0.2 for CVE-2026-65643, 138.0.4 for CVE-2026-67401 and 138.0.8 for CVE-2026-87899 and its companions. The current build at the end of September is around 138.0.10. As with any tier, the major version alone tells you nothing; verify the build against the CVE-to-build mapping.

Verify and decide

After a server reaches 138, check the state of each new feature and set it deliberately:

whmapi1 version
whmapi1 get_tweaksetting key=meridian_enabled 2>/dev/null
whmapi1 get_featurelist_data featurelist=default | grep -iE 'ask_ai|nova|nodejs|mcp'
podman ps --all 2>/dev/null | wc -l

The exact tweak-setting and feature keys vary between 138 builds, so check the changelog for your build if a key returns nothing. A common pitfall is leaving every AI feature enabled in the default feature list because that is how the upgrade left it, then discovering months later that customers have been authorising external agents nobody reviewed. Decide the policy, write it into the feature lists and the tweak settings, and revisit at the next major version.

What changed in cPanel 138 at a glance

What changed in cPanel 138 summary card: cPanel 138 adds the opt-in Meridian interface, an Ask AI assistant, the Nova AI site builder, Model Context Protocol…
In short: cPanel 138 adds the opt-in Meridian interface, an Ask AI assistant, the Nova AI site builder, Model Context Protocol access that lets external AI agents act on accounts through scoped tokens, a Podman-based Node.js Toolkit and in-place…

Official documentation: cPanel & WHM documentation, Linux man pages.

Related guides: Install ImageMagick and PHP Imagick for EA-PHP on AlmaLinux 8/9/10 (and CloudLinux CageFS) · Managing web log retention and Apache log cleanup on cPanel (v136+) · Ubuntu 24.04 or AlmaLinux 9/10 for a new cPanel server in 2026?.

Frequently asked questions

Is the Meridian interface enabled by default in cPanel 138?

No. Meridian is off by default and can be enabled per server, per reseller or per account; Jupiter remains the default theme. The UAPI and WHM API are unchanged, so enabling it affects screens and documentation, not automation.

Can I disable Ask AI and MCP access in cPanel 138?

Yes. Ask AI is a feature-list item that can be removed from any feature list, and MCP authorisation can be disabled at the server level; existing MCP tokens are listed and revocable from WHM.

Does cPanel 138 run on Ubuntu 22.04 or Rocky Linux?

No. 138 requires Ubuntu 24.04 on the Debian side and AlmaLinux 8, 9 (9.5 or later) or 10, or CloudLinux 8 to 10, on the RHEL side. Rocky Linux support ended with version 134.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.