Critical cPanel Vulnerability Lets Hosting Accounts Execute Code as Root
A newly disclosed vulnerability in cPanel’s CalDAV and CardDAV services could allow a user with an ordinary cPanel hosting account to execute code with root privileges and potentially take complete control of a server.
The vulnerability, tracked as CVE-2026-87899, is particularly serious for shared hosting environments because an attacker does not need administrator-level access to exploit it.
According to cPanel, simply having a hosting account is enough to exploit the vulnerability. On a shared server, this means one customer could potentially abuse the flaw to gain control over the entire machine.
A successful attack could allow an intruder to access other customers’ files, modify websites and databases, install malicious software, steal credentials or use the compromised server as a platform for further attacks.
cPanel has released updates addressing the vulnerability in supported versions of cPanel & WHM.
The company also disclosed two additional vulnerabilities.
The first, CVE-2026-87900, affects the WP Toolkit and allows a logged-in cPanel user to perform database modifications involving other accounts.
The second, CVE-2026-68490, affects the CalDAV and CardDAV services and allows a local user to access calendar events and contact information belonging to other accounts.
Unlike the root-level vulnerability, the third issue does not provide root access or the ability to modify the exposed calendar and contact information.
The root-level flaw affects cPanel & WHM version 120 and later. Fixed versions include:
- 11.134.0.57 and later
- 11.136.0.41 and later
- 11.138.0.8 and later
- WP Squared 11.138.1.11 and later
The WP Toolkit vulnerability is fixed in version 6.11.3 or later.
cPanel has not reported evidence that any of the three vulnerabilities have been exploited in the wild. They were also not listed in the CISA Known Exploited Vulnerabilities catalog when the vulnerabilities were reviewed.
However, the potential impact of the root-level vulnerability makes immediate patching particularly important for hosting providers.
Administrators can update cPanel & WHM through the Upgrade to Latest Version option in WHM. cPanel also provides a command-line update method for administrators who manage their servers directly.
The company has not provided a temporary workaround for systems that cannot immediately be updated.
The vulnerabilities were reported by security researcher Ali Mustafa, also known as rz1027. The disclosures are part of a series of recently reported security issues affecting cPanel and related hosting-control software.
Leave a comment