
cPanel Patches Critical Root-Access Flaw in CalDAV Service
cPanel has released urgent patches for three vulnerabilities, the most severe of which allows any hosting account holder to execute code as root and seize full control of the server. The critical flaw, CVE-2026-87899, exists in the CalDAV and CardDAV services and affects cPanel & WHM version 120 and later. A second bug in the WP Toolkit plugin allows users to modify databases belonging to other accounts, while a third issue permits local users to read other accounts' calendar and contact data. The vendor credits researcher Ali Mustafa for identifying all three issues, which were disclosed on September 22. No evidence of active exploitation has been reported yet, but cPanel advises immediate updates to specific fixed versions to mitigate the risks.