VYPR
advisoryPublished Sep 23, 2026· 1 source

Critical cPanel Vulnerabilities Allow Root Access, Database Tampering

Three critical vulnerabilities discovered in cPanel's hosting control panel and associated WP Toolkit plugin could allow hosting account holders to gain root access, modify other users' data, or read sensitive information.

A trio of critical security flaws have been uncovered in cPanel's widely-used hosting control panel, with two of them posing a severe risk by allowing unauthorized users to gain root access to servers and execute arbitrary code. The vulnerabilities, detailed by cPanel on September 22, also include a separate issue that permits account holders to tamper with the databases of other users on the same server.

The most severe of the flaws, tracked as CVE-2026-87899, resides within cPanel's CalDAV and CardDAV service. This service is responsible for managing user calendars and contacts. The vulnerability allows any authenticated hosting account holder to execute commands with root privileges, effectively granting them complete control over the server. This means a compromised or malicious customer account on a shared hosting platform could potentially take over the entire server, impacting all other hosted websites and data.

A second critical vulnerability, CVE-2026-87900, affects the WP Toolkit plugin, a popular tool used for installing and managing WordPress sites. This flaw enables a logged-in cPanel user to modify databases belonging to other accounts. While cPanel has not specified the full extent of potential data manipulation, this could lead to data corruption, unauthorized access, or other malicious alterations of other users' website data.

The third vulnerability, CVE-2026-68490, also impacts the CalDAV and CardDAV service. Unlike the other two, this flaw does not grant root access but allows a local user on the server to read the calendar events and contacts of other accounts. While less severe than the root access exploit, it still represents a significant privacy breach for users storing sensitive personal or business information in their cPanel accounts.

cPanel has moved swiftly to address these issues, releasing patched versions for all affected components. For CVE-2026-87899 and CVE-2026-68490, affected versions of cPanel & WHM 120 and later are fixed in builds 11.134.0.57, 11.136.0.41, and 11.138.0.8, as well as WP Squared 11.138.1.11. The WP Toolkit vulnerability (CVE-2026-87900) is patched in WP Toolkit version 6.11.3 and later.

These vulnerabilities were discovered and reported by researcher Ali Mustafa, who operates under the alias rz1027. Mustafa has been credited with numerous other cPanel and Plesk vulnerabilities disclosed in recent months, often in collaboration with another researcher, abed1526. The disclosure highlights an ongoing trend of critical vulnerabilities being found in widely-used hosting control panel software, underscoring the importance of timely patching for hosting providers and their customers.

Currently, none of the disclosed vulnerabilities have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting that widespread exploitation may not yet be occurring. However, given the severity, particularly the root access exploit, administrators are strongly urged to apply the available patches immediately to mitigate the risk of potential attacks. cPanel has not provided any temporary workarounds for systems that cannot be updated immediately.

The implications of these flaws are significant for the web hosting industry. A successful exploitation of the root access vulnerability could lead to complete server takeovers, data breaches, and widespread service disruptions. The database tampering flaw could also result in significant damage to individual websites and user data. Hosting providers using cPanel are advised to prioritize these updates to ensure the security and integrity of their infrastructure and customer data.

Synthesized by Vypr AI