cPanel Patches Flaws Allowing Root Access and Data Exposure
Share
cPanel has released security updates to address multiple vulnerabilities that could allow a hosting account holder to gain root access and take complete control of a server.
The most critical flaw, identified as CVE-2026-87899, affects the CalDAV and CardDAV services. According to cPanel, a logged-in account holder could exploit this vulnerability to run code with root privileges. In shared hosting environments, where a single server hosts multiple customers, this could allow an individual user to compromise the entire system.
Cross-account and privacy risks
A second vulnerability, CVE-2026-87900, was discovered in the WP Toolkit plugin, which is used to manage WordPress installations. This flaw allows an account holder to perform database modifications in other accounts on the same server.
A third flaw, CVE-2026-68490, also affects the CalDAV and CardDAV services. It allows a local user to read the calendar events and contact information belonging to other accounts. While this does not grant root access or allow data modification, it constitutes a significant breach of user privacy.
Mitigation and updates
The vulnerabilities were identified by security researcher Ali Mustafa, who uses the handle rz1027. While these flaws have been disclosed, they are not currently listed in the CISA Known Exploited Vulnerabilities catalogue, and there is no confirmed evidence of active exploitation.
cPanel has provided fixes for all three issues. Administrators using cPanel & WHM (version 120 and later) should follow the company’s standard update procedures via WHM or the command line. Updating these systems also repairs calendar and contact permissions for existing accounts. For WP Toolkit, users must update to version 6.11.3 or later to mitigate the risk of unauthorised database access.




Leave a Reply