HomeUpdatescPanel fixes three serious security vulnerabilities

cPanel fixes three serious security vulnerabilities

A particularly serious vulnerability in cPanel puts hosting servers at risk, as it could allow a simple, logged-in user to execute code with root and essentially gain complete control of the server. cPanel disclosed the issue on September 22, while also releasing fixes for the critical vulnerability, as well as for two other security issues affecting the platform.

Article image: New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

This issue is particularly acute in shared hosting environments , where a physical server hosts accounts from many different customers. In such an infrastructure, the ability of one account to escape the intended isolation limits can create a cascading risk for the entire server.

The CVE-2026-87899 vulnerability and root access

The most serious of the three vulnerabilities is listed as CVE-2026-87899 and affects cPanel's CalDAV and CardDAV services . According to the company, a user with a valid cPanel account could exploit the flaw to execute code with root privileges.

Root is the highest level of privilege. An attacker who manages to gain such privileges is no longer limited to their own account. They can potentially access files and services on the server, modify settings, install malware , or use the system as a launching pad for further attacks.

See also: cPanel: Critical SQL vulnerability allows execution as root

What is particularly worrying is that cPanel does not mention any additional requirement for exploitation beyond having an account. Therefore, on a shared server, the problem does not only concern infrastructure administrators, but potentially any customer with an account.

Second problem in WP Toolkit

At the same time, cPanel fixed a second vulnerability, CVE-2026-87900, which is found in WP Toolkit, a tool widely used for installing, configuring, and managing WordPress websites.

The vulnerability allows a logged-in cPanel user to make modifications to databases belonging to other accounts. The company has not publicly clarified the exact scope of changes that can be made, nor whether the vulnerability also allows data to be read.

This creates an additional risk in environments where multiple WordPress sites coexist on the same server, as databases often contain critical information, from user data to application settings and website content.

Calendar and contacts leak

The third vulnerability, CVE-2026-68490, also affects the CalDAV and CardDAV services. In this case, a local user on the server could gain access to calendar events and contacts from other accounts.

This vulnerability does not lead to root access or allow data modification, however it can create a significant confidentiality issue. Exposing personal or business contacts and scheduled meetings could provide useful information to a malicious user.

cPanel vulnerability - SecNews.gr

Which versions need updating?

cPanel has released fixes for the affected versions. For CVE-2026-87899 and CVE-2026-68490, the fixed versions include 11.134.0.57, 11.136.0.41, and 11.138.0.8, as well as the corresponding version of WP Squared.

For WP Toolkit, version 6.11.3 or later, as previous versions, up to and including 6.11.2-10794, are affected by the related issue.

See also: cPanel CVE-2026-65643: Critical vulnerability gives root access

cPanel & WHM administrators can upgrade via WHM or use the cPanel update process. WP Toolkit has a separate upgrade mechanism.

There are no signs of active exploitation

So far, the relevant announcements do not mention any active exploitation of the three vulnerabilities. At the same time, during the relevant audit on September 23, these CVEs did not appear on the CISA Known Exploited Vulnerabilities (KEV) list

This, however, does not mean that administrators can delay installing patches. CVE-2026-87899 in particular is of increased interest due to the possibility of switching from a simple account to root privileges.

cPanel critical vulnerability CVE-2026-58048 SQL injection database root

cPanel attributes all three discoveries to researcher Ali Mustafa, also known as rz1027. The revelations are part of a broader series of investigations that have led to the identification of several security issues in cPanel and Plesk in recent weeks.

See also: CISA: Vulnerability in LiteSpeed ​​cPanel Plugin allows privilege escalation

For hosting providers, the key message is clear: installing available updates should be an immediate priority, especially on shared servers where a vulnerable service can affect many different customers and websites.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS