New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
cPanel flaws allow hosting account holders to gain root access and control servers.
Summary
Two critical vulnerabilities have been disclosed in cPanel's CalDAV/CardDAV service and WP Toolkit plugin. The first allows any cPanel account holder to execute code as root, granting full server control. The second enables an account holder to modify databases belonging to other accounts. A third, less severe flaw allows local users to read other accounts' calendar and contact data. cPanel has released patches for all issues.
Full text
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Swati KhandelwalSep 23, 2026Vulnerability / Web Security A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other accounts' calendar events and contacts, but not change them or gain root access. cPanel lists no requirements for the root flaw other than having an account. On a shared server where a hosting provider sells accounts to the public, that means any customer could use it. So could anyone who gets hold of a customer's login. The three flaws and the versions that fix them: Flaw Where What it allows, according to cPanel Affected Fixed in CVE-2026-87899 CalDAV and CardDAV A logged-in account holder can run code as root cPanel & WHM version 120 and later 11.134.0.57 or later 11.136.0.41 or later 11.138.0.8 or later WP Squared 11.138.1.11 or later CVE-2026-87900 WP Toolkit A logged-in cPanel user can change databases in other accounts WP Toolkit 6.11.2-10794 and older WP Toolkit 6.11.3 or later CVE-2026-68490 CalDAV and CardDAV A local user can read other accounts' calendar events and contacts cPanel & WHM version 120 and later 11.134.0.57 or later 11.136.0.41 or later 11.138.0.8 or later WP Squared 11.138.1.11 or later The WP Toolkit bug is in how the plugin handles commands that create databases. cPanel says only that a logged-in cPanel user could "perform database modifications in other accounts." It does not say what changes are possible, whether data from other accounts can also be read, or whether the user needs access to WP Toolkit itself. WP Toolkit is also available for Plesk, another hosting control panel from the same company, WebPros. cPanel has not said whether the Plesk version is affected. None of the three advisories mentions exploitation or gives a way to check whether a server was attacked before it was updated. The flaws were not in CISA's Known Exploited Vulnerabilities catalog when The Hacker News checked on September 23. cPanel credits all three flaws to Ali Mustafa, a researcher who goes by rz1027. Vendor advisories and CVE records credit him with at least seven cPanel and Plesk flaws disclosed since August 27, three of them shared with a researcher known as abed1526. They include a September 8 flaw in cPanel's EmailTrack feature that let an account with mail privileges run code as root, cPanel said at the time. Plesk fixed two more on September 10, in how its Backup Manager restores files and how it handles backup headers. It said each could let a customer take over the whole server. How to Update cPanel gives separate update instructions for cPanel & WHM and for WP Toolkit. WP Toolkit is installed as its own package, wp-toolkit-cpanel, with its own update. cPanel & WHM (CVE-2026-87899 and CVE-2026-68490): follow cPanel's update steps. In WHM, go to Home / cPanel / Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root. The update also repairs calendar and contact permissions for existing accounts. WP Toolkit (CVE-2026-87900): update to version 6.11.3 or later with this command: bash <(curl https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -O - https://wp-toolkit.plesk.com/cPanel/installer.sh) --version 6.11.3 The calendar flaws affect version 120 and later, but cPanel lists fixed builds only for the 134, 136, and 138 release lines and for WP Squared. cPanel offers no temporary workaround for servers that cannot be updated yet. For WP Toolkit, only the manual command is given, and whether automatic updates will install 6.11.3 is not stated. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE privilege escalation, Vulnerability, Web Security, WordPress ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header
Indicators of Compromise
- cve — CVE-2026-87899
- cve — CVE-2026-87900
- cve — CVE-2026-68490