New cPanel Flaw Lets Hosting Accounts Gain Root Control of Shared Servers
cPanel patches CVE-2026-87899, a serious CalDAV/CardDAV flaw that allows an authenticated hosting account to execute code as root and potentially take full control of a shared server.

cPanel has patched a serious security vulnerability that could allow an authenticated hosting account holder to execute code as root, potentially taking complete control of a shared hosting server.
Tracked as CVE-2026-87899, the vulnerability affects cPanel's CalDAV and CardDAV functionality and impacts cPanel & WHM version 120 and later. cPanel disclosed the flaw on September 22, 2026.
CVE-2026-87899 at a Glance
| Detail | Information |
|---|---|
| CVE | CVE-2026-87899 |
| Component | CalDAV / CardDAV |
| Requirement | Authenticated cPanel account |
| Impact | Code execution as root |
| Affected | cPanel & WHM v120 and later |
| Risk | Full server takeover |
| Active Exploitation | None publicly reported |
The vulnerability is especially dangerous in shared hosting environments, where multiple customers have separate cPanel accounts on the same physical or virtual server. cPanel says successful exploitation gives an attacker root-level code execution and therefore full control of the server.
How Serious Is the Flaw?
Unlike an unauthenticated internet-facing RCE, CVE-2026-87899 requires the attacker to already have access to a cPanel account.
However, cPanel lists no additional privilege requirement beyond being an authenticated account holder. This means a malicious hosting customer—or an attacker who compromises a customer's account—could potentially escalate from control of a single hosting account to control of the entire server.
The potential attack path is:
cPanel Account → CalDAV/CardDAV Vulnerability → Privilege Escalation → Root Code Execution → Full Server Control
Once root access is obtained, an attacker could potentially access other hosted accounts, modify websites and databases, steal credentials, install malware, establish persistence, or interfere with server security controls.
Two Additional Vulnerabilities Patched
cPanel also fixed two related security issues disclosed at the same time.
| CVE | Component | Impact |
|---|---|---|
| CVE-2026-87899 | CalDAV/CardDAV | Root code execution |
| CVE-2026-87900 | WP Toolkit | Modify databases belonging to other accounts |
| CVE-2026-68490 | CalDAV/CardDAV | Read other users' calendars and contacts |
CVE-2026-87900 affects WP Toolkit 6.11.2-10794 and earlier. A logged-in cPanel user could perform database modifications affecting other accounts.
CVE-2026-68490, meanwhile, allows a local user to access calendar events and contacts belonging to other cPanel accounts, breaking tenant isolation.
Fixed Versions
Administrators should upgrade cPanel & WHM to:
- 11.134.0.57 or later
- 11.136.0.41 or later
- 11.138.0.8 or later
- WP Squared 11.138.1.11 or later
WP Toolkit users should separately upgrade to version 6.11.3 or later to address CVE-2026-87900.
Administrators can update cPanel through:
WHM → Home → cPanel → Upgrade to Latest Version
or run:
/usr/local/cpanel/scripts/upcp --force
cPanel says the update also repairs affected calendar and contact permissions for existing accounts.
No Active Exploitation Reported
At the time of disclosure, the advisories did not report active exploitation of these vulnerabilities, and they were not listed in CISA's Known Exploited Vulnerabilities catalog when checked on September 23.
However, hosting providers should prioritize patching because compromise of a single customer account could potentially escalate into a server-wide security incident.
Security Takeaway
CVE-2026-87899 breaks one of the most important security boundaries in shared hosting: isolation between a customer account and the underlying server.
The risk can be summarized as:
Hosting Account → Privilege Escalation → Root Execution → Entire Server Compromise
Hosting providers should update cPanel immediately and review previously vulnerable servers for suspicious privilege escalation, unexpected root processes, new accounts, modified system files, persistence mechanisms, and unusual activity originating from customer accounts.
Related reporting
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.


