TL;DR
On September 22, 2026, cPanel published security advisories addressing three security flaws across its hosting platform. These cPanel security vulnerabilities allow authenticated attackers to gain root access and manipulate foreign databases. System administrators must apply the latest updates to secure shared hosting servers.
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
Web hosting providers run cPanel on millions of shared servers worldwide. Consequently, isolation between tenants is vital for web safety. The most dangerous flaw allows local account holders to compromise the entire server. According to the advisory, “Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.” Furthermore, an attacker can modify databases belonging to neighboring websites. Currently, security researchers have not confirmed active exploitation in the wild. Additionally, no public proof-of-concept exploit code exists. However, shared hosting environments face urgent exposure until administrators apply patches.
How The Attack Works
The primary flaw resides in the platform’s calendar and address book components. In its bulletin for CVE-2026-87899, cPanel explains that an authenticated user can escalate privileges through CalDAV and CardDAV handling. The service runs privileged background tasks that fail to sanitize user input. As a result, an attacker elevates permissions directly to root.
Meanwhile, a related permissions flaw (CVE-2026-68490) in CalDAV and CardDAV storage exposes sensitive data. The advisory notes, “A permissions issue could allow a local user on the same server to access calendar and contact data belonging to other accounts.”
Finally, a flaw (CVE-2026-87900) in WP Toolkit database creation breaks tenant boundaries. The utility mishandles database-creation commands. Consequently, an authenticated cPanel user can alter databases owned by other accounts on the same server.
Affected Versions
These cPanel security vulnerabilities impact cPanel and WHM version 120 and later. In addition, the database flaw affects WP Toolkit versions 6.11.2-10794 and older.
Patch Or Mitigation Steps
Administrators should upgrade cPanel and WHM to version 11.138.0.8 or later immediately. The vendor confirmed that updating repairs storage permissions on existing accounts. Furthermore, administrators must update WP Toolkit to version 6.11.3 using the official installer script.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!