Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-87899 Vulnerabilities

New cPanel Flaw Lets Hosting Accounts Gain Root Control of Shared Servers

cPanel patches CVE-2026-87899, a serious CalDAV/CardDAV flaw that allows an authenticated hosting account to execute code as root and potentially take full control of a shared server.

cPanel has patched a serious security vulnerability that could allow an authenticated hosting account holder to execute code as root, potentially taking complete control of a shared hosting server.

Tracked as CVE-2026-87899, the vulnerability affects cPanel's CalDAV and CardDAV functionality and impacts cPanel & WHM version 120 and later. cPanel disclosed the flaw on September 22, 2026.

CVE-2026-87899 at a Glance

Detail Information
CVE CVE-2026-87899
Component CalDAV / CardDAV
Requirement Authenticated cPanel account
Impact Code execution as root
Affected cPanel & WHM v120 and later
Risk Full server takeover
Active Exploitation None publicly reported

The vulnerability is especially dangerous in shared hosting environments, where multiple customers have separate cPanel accounts on the same physical or virtual server. cPanel says successful exploitation gives an attacker root-level code execution and therefore full control of the server.

How Serious Is the Flaw?

Unlike an unauthenticated internet-facing RCE, CVE-2026-87899 requires the attacker to already have access to a cPanel account.

However, cPanel lists no additional privilege requirement beyond being an authenticated account holder. This means a malicious hosting customer—or an attacker who compromises a customer's account—could potentially escalate from control of a single hosting account to control of the entire server.

The potential attack path is:

cPanel Account → CalDAV/CardDAV Vulnerability → Privilege Escalation → Root Code Execution → Full Server Control

Once root access is obtained, an attacker could potentially access other hosted accounts, modify websites and databases, steal credentials, install malware, establish persistence, or interfere with server security controls.

Two Additional Vulnerabilities Patched

cPanel also fixed two related security issues disclosed at the same time.

CVE Component Impact
CVE-2026-87899 CalDAV/CardDAV Root code execution
CVE-2026-87900 WP Toolkit Modify databases belonging to other accounts
CVE-2026-68490 CalDAV/CardDAV Read other users' calendars and contacts

CVE-2026-87900 affects WP Toolkit 6.11.2-10794 and earlier. A logged-in cPanel user could perform database modifications affecting other accounts.

CVE-2026-68490, meanwhile, allows a local user to access calendar events and contacts belonging to other cPanel accounts, breaking tenant isolation.

Fixed Versions

Administrators should upgrade cPanel & WHM to:

  • 11.134.0.57 or later
  • 11.136.0.41 or later
  • 11.138.0.8 or later
  • WP Squared 11.138.1.11 or later

WP Toolkit users should separately upgrade to version 6.11.3 or later to address CVE-2026-87900.

Administrators can update cPanel through:

WHM → Home → cPanel → Upgrade to Latest Version

or run:

/usr/local/cpanel/scripts/upcp --force

cPanel says the update also repairs affected calendar and contact permissions for existing accounts.

No Active Exploitation Reported

At the time of disclosure, the advisories did not report active exploitation of these vulnerabilities, and they were not listed in CISA's Known Exploited Vulnerabilities catalog when checked on September 23.

However, hosting providers should prioritize patching because compromise of a single customer account could potentially escalate into a server-wide security incident.

Security Takeaway

CVE-2026-87899 breaks one of the most important security boundaries in shared hosting: isolation between a customer account and the underlying server.

The risk can be summarized as:

Hosting Account → Privilege Escalation → Root Execution → Entire Server Compromise

Hosting providers should update cPanel immediately and review previously vulnerable servers for suspicious privilege escalation, unexpected root processes, new accounts, modified system files, persistence mechanisms, and unusual activity originating from customer accounts.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.