Site icon TechloMedia

cPanel patches critical flaw that could let hosting users gain root access

cpanel

Photo: WebPros

cPanel has patched three security vulnerabilities affecting its hosting control panel and WP Toolkit, including a critical flaw that could allow an authenticated cPanel account holder to execute code with root privileges and gain full control of the server.

The most serious issue is tracked as CVE-2026-87899 and affects the CalDAV and CardDAV functionality in cPanel & WHM. According to cPanel, an authenticated account holder can exploit the vulnerability to escalate privileges and execute code as the root user. Successful exploitation would give the attacker full control of the affected server.

The vulnerability affects cPanel & WHM version 120 and later. This is particularly important for shared hosting environments because an attacker does not need WHM administrator access to trigger the issue. A valid cPanel account is enough according to cPanel’s advisory. This means a malicious hosting customer, or someone who has obtained the credentials of a customer, could potentially target the underlying server.

cPanel has released fixes through several release branches. The patched versions are 11.134.0.57 or later, 11.136.0.41 or later, and 11.138.0.8 or later. The corresponding WP Squared release is 11.138.1.11 or later. cPanel recommends updating to the latest available patched version.

A second vulnerability, CVE-2026-87900, affects the WP Toolkit plugin used to install and manage WordPress websites. The flaw is related to how WP Toolkit handles database creation commands. cPanel says an authenticated cPanel user could exploit the issue to perform database modifications in other accounts.

The vulnerability affects WP Toolkit 6.11.2-10794 and older versions. It has been fixed in WP Toolkit 6.11.3 and later. cPanel has not provided further public details about exactly which database changes could be made or whether an attacker could also read data belonging to other accounts.

The third issue, CVE-2026-68490, is another vulnerability in cPanel’s CalDAV and CardDAV functionality. Unlike the root privilege escalation flaw, this issue is related to permissions and allows a local user on the server to access calendar events and contacts belonging to other accounts. cPanel says the vulnerability does not allow the attacker to modify that information or obtain root access.

CVE-2026-68490 affects cPanel & WHM version 120 and later and is fixed in the same cPanel builds as CVE-2026-87899: 11.134.0.57 or later, 11.136.0.41 or later, and 11.138.0.8 or later. WP Squared users should update to 11.138.1.11 or later. The update also fixes permissions for both new and existing calendar and address book storage.

cPanel vulnerabilities and fixed versions

CVEComponentImpactFixed version
CVE-2026-87899CalDAV/CardDAVAuthenticated user can execute code as root11.134.0.57+, 11.136.0.41+, 11.138.0.8+
CVE-2026-87900WP ToolkitAuthenticated user can modify databases belonging to other accountsWP Toolkit 6.11.3+
CVE-2026-68490CalDAV/CardDAVLocal user can read other accounts’ calendar and contact data11.134.0.57+, 11.136.0.41+, 11.138.0.8+

cPanel credited security researcher Ali Mustafa, also known as rz1027, with reporting all three vulnerabilities. The company has not disclosed any known exploitation of these specific flaws in its advisories.

For servers running cPanel & WHM, administrators can update through WHM > Home > cPanel > Upgrade to Latest Version. cPanel also documents a forced update using the upcp script for administrators who prefer to update from the command line.

WP Toolkit is updated separately. cPanel’s advisory provides an installer command that upgrades the plugin to version 6.11.3. Hosting providers using WP Toolkit should therefore make sure the plugin itself is updated rather than relying only on a cPanel & WHM update.

The disclosures come shortly after another serious cPanel security issue was patched earlier this month. On September 8, cPanel fixed CVE-2026-67401, which affected its EmailTrack functionality and could allow an authenticated account holder with mail-related privileges to create arbitrary files and ultimately execute code as root.

Exit mobile version