cPanel CVE-2026-87899
A cPanel Account Can Become Root.
A flaw in cPanel's calendar and contacts service lets anyone holding a cPanel account on the server run code as root. cPanel shipped fixed builds on September 22, 2026. If you run cPanel & WHM, check your version tonight.
Published September 29, 2026 · Last updated October 1, 2026
By Ace-Host, Southfield, Michigan: hosting on our own network (AS22878) since 2003
What happened
On September 22, 2026, cPanel published an advisory for CVE-2026-87899, a flaw in cPanel's CalDAV and CardDAV functionality, the service that syncs calendars and contacts. In cPanel's words, an authenticated cPanel account holder can escalate their privileges through it, and successful exploitation leads to code execution as the root user, giving an attacker full control of the server.
The CVE record, published September 23, scores it CVSS 4.0 9.4, Critical (vector AV:N/AC:L/AT:N/PR:L/UI:N): reachable over the network, low complexity, and it requires a cPanel login, not an admin one. The weakness is classed as CWE-250, execution with unnecessary privileges. cPanel credits Ali Mustafa (rz1027) with reporting it. The advisory gives no further technical detail, and neither do we.
The same builds fix a second CalDAV/CardDAV issue, CVE-2026-68490, scored CVSS 4.0 8.2, High: a local user on the same server can read other accounts' calendar events and contacts. cPanel says it does not allow changing that data and does not grant root. Updating repairs the permissions on existing accounts as well as new ones.
The same day, cPanel published a third advisory, for WP Toolkit, the WordPress manager that ships with cPanel: CVE-2026-87900. The CVE record, published September 23, describes argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier that lets a logged-in user read arbitrary files and execute arbitrary code across customer accounts. It scores it CVSS 4.0 9.4, Critical, with the same need for a cPanel login and the same reporter. The weakness is classed as CWE-88, argument injection. WP Toolkit has its own version number, separate from the cPanel build, so the builds listed below do not tell you whether it is fixed.
Who is affected
Servers running cPanel & WHM version 120 or later that have not reached a patched build. The fixed builds are:
- 11.134.0.57 or later
- 11.136.0.41 or later
- 11.138.0.8 or later
- WP Squared: 11.138.1.11 or later
The exposure is the people who hold cPanel logins on the server. On a server where every account is yours, it is one login away from root. On a shared or reseller server, every customer account is a way in. To see which build you run, log in as root over SSH and read the version file:
cat /usr/local/cpanel/version
A result such as 11.136.0.40 is affected; 11.136.0.41 is fixed. If your server reports a version from 11.120 through 11.132, cPanel lists no patched build for it: the fix is to move up to one of the builds above.
For CVE-2026-87900, the affected range is WP Toolkit for cPanel 6.11.2-10794 and earlier; the fixed version is 6.11.3-10850 or later.
What to do
Update cPanel & WHM. As root over SSH, or in WHM's Terminal, run cPanel's documented update command, then read the version again to confirm you are on a fixed build:
/usr/local/cpanel/scripts/upcp --force
cat /usr/local/cpanel/version
Without a shell, log in to WHM as root and go to Home » cPanel » Upgrade to Latest Version, then click Click to Upgrade.
If you cannot patch tonight: neither advisory offers a workaround. Updating is the fix cPanel gives, so schedule it as soon as you can, and until then treat every cPanel login on that server as able to reach root.
For WP Toolkit, confirm the server reports 6.11.3-10850 or later. We could not read cPanel's WP Toolkit advisory this run, so we do not print an update command for it here; follow cPanel's advisory rather than a command we have not checked.
Sources
- cPanel, Security: CVE-2026-87899 Vulnerability in cPanel's CalDAV/CardDAV, September 22, 2026. Fetched September 29, 2026.
- cPanel, Security: CVE-2026-68490 Vulnerability in cPanel's CalDAV/CardDAV Functionality, September 22, 2026. Fetched September 29, 2026.
- CVE record, CVE-2026-87899 (CNA: HackerOne; CVSS 4.0 9.4). Fetched September 29, 2026.
- CVE record, CVE-2026-68490 (CNA: HackerOne; CVSS 4.0 8.2). Fetched September 29, 2026.
- CVE record, CVE-2026-87900 (CNA: HackerOne; CVSS 4.0 9.4; affected WP Toolkit for cPanel 6.11.2-10794 and earlier, fixed 6.11.3-10850). Fetched October 1, 2026.
- cPanel, Security: CVE-2026-87900 Vulnerability in WP Toolkit Database Creation, September 22, 2026. Could not be fetched October 1, 2026; cited by the CVE record.
- cPanel, How do I update cPanel/WHM? Fetched September 29, 2026.
- cPanel support community, a thread showing
cat /usr/local/cpanel/versionand its output. Fetched September 29, 2026.
These three are the latest of several this year. cPanel's 2026 security releases, by date, lists each one with its score and fixed builds.
Leaving cPanel does not end patching: every server needs updates, with a panel or without one. It does end the cPanel license. If that trade interests you, here is what moving off cPanel involves.