cPanel Patches Critical Root-Access Flaw in CalDAV Service

cPanel has released urgent patches for three vulnerabilities, the most severe of which allows any hosting account holder to execute code as root and seize full control of the server. The critical flaw, CVE-2026-87899, exists in the CalDAV and CardDAV services and affects cPanel & WHM version 120 and later. A second bug in the WP Toolkit plugin allows users to modify databases belonging to other accounts, while a third issue permits local users to read other accounts' calendar and contact data. The vendor credits researcher Ali Mustafa for identifying all three issues, which were disclosed on September 22. No evidence of active exploitation has been reported yet, but cPanel advises immediate updates to specific fixed versions to mitigate the risks.
Key points
- CVE-2026-87899 allows any logged-in cPanel user to run code as root, granting full server control without additional prerequisites.
- CVE-2026-87900 in the WP Toolkit plugin enables users to perform database modifications on other accounts, though the specific scope of these changes is not detailed.
- CVE-2026-68490 allows local users to read other accounts' calendar events and contacts but does not permit changes or root access.
- Fixed versions include cPanel & WHM 11.134.0.57, 11.136.0.41, and 11.138.0.8, as well as WP Toolkit 6.11.3.
- The flaws were identified by researcher Ali Mustafa, who has disclosed at least seven cPanel and Plesk vulnerabilities since late August.
Background
This incident follows a pattern of critical vulnerabilities in web hosting control panels, similar to the macOS screen-sharing flaw disclosed in August 2026 that allowed remote root access. While the earlier macOS issue involved active exploitation with Monero miners, the current cPanel flaws have not yet been listed in the CISA Known Exploited Vulnerabilities catalog. The recent disclosures highlight ongoing security challenges in widely used server management software, particularly regarding privilege escalation and cross-account data access.
How outlets are covering it
The Hacker News provides a detailed technical breakdown of the three CVEs, emphasizing the severity of the root-access flaw and the lack of a temporary workaround. It notes that cPanel has not confirmed if the Plesk version of WP Toolkit is affected. In contrast, secondary sources gbhackers.com and CyberSecurityNews appear to be referencing a different, potentially unrelated cPanel authentication bypass vulnerability (CVE-2026-41940) involving Mirai malware, which is not mentioned in the primary source. This discrepancy suggests that while the primary source focuses on the newly disclosed CalDAV and WP Toolkit flaws, other outlets may be conflating or reporting on a separate, older authentication issue. The primary source remains the authoritative reference for the specific CVEs disclosed on September 22.
Why it matters
The critical nature of CVE-2026-87899 poses a significant risk to shared hosting environments, where a single compromised account could lead to the compromise of the entire server and all other customers' data. The absence of a workaround means that immediate patching is the only mitigation strategy. Given the widespread use of cPanel in the web hosting industry, the potential for large-scale server compromise is high if updates are not applied promptly. The involvement of a prolific researcher also suggests that further vulnerabilities in the cPanel ecosystem may be forthcoming.
What to watch
Hosting providers and users must immediately update their cPanel & WHM installations to version 11.134.0.57 or later, and WP Toolkit to version 6.11.3 or later, to mitigate the risks. Administrators should verify that automatic updates are enabled for WP Toolkit, as the vendor has not confirmed if this will happen automatically. Security teams should monitor for any signs of exploitation, although no indicators of compromise have been provided by cPanel. The vendor is expected to continue monitoring for further vulnerabilities, given the recent string of disclosures by Ali Mustafa.
Want the full story? Read the original reporting
Read on The Hacker News