Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-24 · updated: 2026-09-24 · tags: [cve, cpanel, hosting, privilege-escalation, rce, shared-hosting] · confidence: high · severity: critical · affected_sectors: [technology, retail, education, government] · au_impact: true

CVE-2026-87899

Summary

A privilege-escalation flaw in cPanel's CalDAV and CardDAV service that lets anyone holding a hosting account execute code with root privileges on the server. NVD records it at CVSS 4.0 9.4 (Critical), describing it as "execution with unnecessary privileges" allowing "remote authenticated users to execute arbitrary code with root privileges". On a shared hosting platform the authentication requirement is not a meaningful barrier, because the attacker can be an ordinary customer — or anyone who has obtained a customer's login.

Details

cPanel published the fix on 22 September alongside two further flaws in the same service and one in the WP Toolkit plugin:

CVE Where What it allows Fixed in
CVE-2026-87899 CalDAV / CardDAV A logged-in account holder runs code as root cPanel & WHM 11.134.0.57+, 11.136.0.41+, 11.138.0.8+; WP Squared 11.138.1.11+
CVE-2026-87900 WP Toolkit A logged-in cPanel user modifies databases in other accounts WP Toolkit 6.11.3+
CVE-2026-68490 CalDAV / CardDAV A local user reads other accounts' calendar events and contacts cPanel & WHM 11.134.0.57+, 11.136.0.41+, 11.138.0.8+

cPanel lists no prerequisite for the root flaw beyond having an account, so on a shared server where a provider sells accounts to the public, any customer could use it. None of the three advisories mentions exploitation or gives a way to check whether a server was targeted. WP Toolkit is also published for Plesk, which shares the WebPros parent, and cPanel has not said whether the Plesk version is affected.

Australian Significance

Australia's web-hosting market is dominated by cPanel-based shared hosting resold to small businesses, community organisations, schools and local government, which is exactly the population with the least capacity to verify whether a host has patched. For operators of cPanel servers the risk is a single low-privilege account converting into full server control — the worst-case shape for public multi-tenant hosting — so verifying the fixed build numbers on every server, and confirming whether resold accounts sit on hosts that have, is the immediate action.

Sources