Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: caldav (1 article)Clear

cPanel flaw lets any hosting account run code as root and seize the server

cPanel disclosed a flaw in its CalDAV and CardDAV service, CVE-2026-87899, that lets any logged-in hosting account run code as root and take full control of the server. It lists no requirement beyond having an account, so on a shared server any customer, or anyone with a stolen customer login, could exploit it. cPanel also fixed a WP Toolkit bug, CVE-2026-87900, letting an account holder alter other accounts' databases, and a third issue, CVE-2026-68490, letting a local user read other accounts' calendars and contacts. Fixes ship across cPanel and WHM version 120 and later branches, including builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 or later, plus WP Toolkit 6.11.3.

Check
Identify cPanel and WHM servers on version 120 branches, apply the fixed builds now, and prioritize shared hosting where any customer account is a threat.
Affected
Any cPanel account on an unpatched server can run code as root through the CalDAV and CardDAV service and take full control of the host.
Fix
Update cPanel and WHM to the fixed 11.134, 11.136, or 11.138 builds and WP Toolkit 6.11.3, then audit accounts and reset exposed logins.