A critical security flaw in cPanel’s CalDAV and CardDAV service could allow a logged-in hosting account user to run code with root privileges and take full control of a server, according to cPanel.

The vulnerability, tracked as CVE-2026-87899, was disclosed on September 22 and affects cPanel & WHM version 120 and later. The company says the flaw does not require any additional privileges beyond having a cPanel account. On shared hosting servers, this could mean a regular customer may be able to compromise the entire server. Anyone who gains access to a customer’s hosting credentials could potentially abuse the same weakness.

A second vulnerability, CVE-2026-87900, affects the WP Toolkit plugin used to install and manage WordPress websites. The flaw allows a logged-in cPanel user to make database modifications affecting other hosting accounts. cPanel has not provided details about exactly what database changes are possible or whether information from other accounts can also be accessed.

The third vulnerability, CVE-2026-68490, is also located in the CalDAV and CardDAV service. It allows a local user to read calendar events and contacts belonging to other accounts. Unlike the critical root-level flaw, this issue does not allow attackers to modify the information or gain root access.

cPanel has released fixes for all three vulnerabilities. CVE-2026-87899 and CVE-2026-68490 are fixed in cPanel versions 11.134.0.57, 11.136.0.41, 11.138.0.8 and later, as well as WP Squared 11.138.1.11 and later. The WP Toolkit vulnerability is fixed in version 6.11.3 and later.

READ
Google Fined €403 Million Over GDPR Location Data Violations

The WP Toolkit issue is related to the way the plugin handles commands used to create databases. cPanel describes the impact as allowing a logged-in user to perform database modifications in other accounts, but the company has not disclosed further technical details.

WP Toolkit is also available for Plesk, another hosting control panel operated by WebPros. cPanel has not said whether the Plesk version is affected by the same vulnerability.

The advisories do not mention any confirmed exploitation of the vulnerabilities or provide a method for checking whether a server was compromised before it was patched. The flaws were also not listed in CISA’s Known Exploited Vulnerabilities catalog when they were checked on September 23.

All three vulnerabilities were credited to security researcher Ali Mustafa, also known as rz1027. He has been credited with several cPanel and Plesk vulnerabilities disclosed since late August, including a September 8 cPanel flaw in the EmailTrack feature that could also allow an account with mail privileges to execute code as root.

cPanel is urging administrators to update affected systems. The company provides separate update procedures for cPanel & WHM and WP Toolkit. For cPanel & WHM, administrators can upgrade through WHM by going to Home > cPanel > Upgrade to Latest Version or run the official update command as root. WP Toolkit can be updated separately to version 6.11.3 or later.

cPanel says the update also repairs calendar and contact permissions for existing accounts. No temporary workaround has been provided for servers that cannot be updated, making the available security updates particularly important for affected hosting environments.


Buy ExpressVPN with PayPal or Credit Card
READ
Cisco ISE Flaw Under Active Exploitation With Maximum Severity Score

Advertisement