CVE-2026-87899
Summary
A privilege-escalation flaw in cPanel's CalDAV and CardDAV service that lets anyone holding a hosting account execute code with root privileges on the server. NVD records it at CVSS 4.0 9.4 (Critical), describing it as "execution with unnecessary privileges" allowing "remote authenticated users to execute arbitrary code with root privileges". On a shared hosting platform the authentication requirement is not a meaningful barrier, because the attacker can be an ordinary customer — or anyone who has obtained a customer's login.
Details
cPanel published the fix on 22 September alongside two further flaws in the same service and one in the WP Toolkit plugin:
| CVE | Where | What it allows | Fixed in |
|---|---|---|---|
| CVE-2026-87899 | CalDAV / CardDAV | A logged-in account holder runs code as root | cPanel & WHM 11.134.0.57+, 11.136.0.41+, 11.138.0.8+; WP Squared 11.138.1.11+ |
| CVE-2026-87900 | WP Toolkit | A logged-in cPanel user modifies databases in other accounts | WP Toolkit 6.11.3+ |
| CVE-2026-68490 | CalDAV / CardDAV | A local user reads other accounts' calendar events and contacts | cPanel & WHM 11.134.0.57+, 11.136.0.41+, 11.138.0.8+ |
cPanel lists no prerequisite for the root flaw beyond having an account, so on a shared server where a provider sells accounts to the public, any customer could use it. None of the three advisories mentions exploitation or gives a way to check whether a server was targeted. WP Toolkit is also published for Plesk, which shares the WebPros parent, and cPanel has not said whether the Plesk version is affected.
Australian Significance
Australia's web-hosting market is dominated by cPanel-based shared hosting resold to small businesses, community organisations, schools and local government, which is exactly the population with the least capacity to verify whether a host has patched. For operators of cPanel servers the risk is a single low-privilege account converting into full server control — the worst-case shape for public multi-tenant hosting — so verifying the fixed build numbers on every server, and confirming whether resold accounts sit on hosts that have, is the immediate action.