Download Privacy Needle App

Type to search

Cybersecurity

cPanel Patches Flaws Allowing Root Access and Data Exposure

Share

cPanel has released security updates to address multiple vulnerabilities that could allow a hosting account holder to gain root access and take complete control of a server.

The most critical flaw, identified as CVE-2026-87899, affects the CalDAV and CardDAV services. According to cPanel, a logged-in account holder could exploit this vulnerability to run code with root privileges. In shared hosting environments, where a single server hosts multiple customers, this could allow an individual user to compromise the entire system.

Cross-account and privacy risks

A second vulnerability, CVE-2026-87900, was discovered in the WP Toolkit plugin, which is used to manage WordPress installations. This flaw allows an account holder to perform database modifications in other accounts on the same server.

A third flaw, CVE-2026-68490, also affects the CalDAV and CardDAV services. It allows a local user to read the calendar events and contact information belonging to other accounts. While this does not grant root access or allow data modification, it constitutes a significant breach of user privacy.

Mitigation and updates

The vulnerabilities were identified by security researcher Ali Mustafa, who uses the handle rz1027. While these flaws have been disclosed, they are not currently listed in the CISA Known Exploited Vulnerabilities catalogue, and there is no confirmed evidence of active exploitation.

cPanel has provided fixes for all three issues. Administrators using cPanel & WHM (version 120 and later) should follow the company’s standard update procedures via WHM or the command line. Updating these systems also repairs calendar and contact permissions for existing accounts. For WP Toolkit, users must update to version 6.11.3 or later to mitigate the risk of unauthorised database access.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.