securityonline.info 24 Sept 2026, 01:09 UTC

cPanel Flaws Let Local Users Seize Shared Hosting Servers

cPanel Flaws Let Local Users Seize Shared Hosting Servers
CyberSIXT Evidence Panel Source marked as original reporting

ON 22 September 2026, cPanel disclosed three vulnerabilities affecting its hosting platform. The most serious, CVE-2026-87899, is a privilege-escalation flaw in the CalDAV and CardDAV components. An authenticated local user can exploit unsanitised input handled by privileged background tasks to execute code as root, potentially gaining full control of a shared server. CVE-2026-68490 is a permissions weakness that can expose calendar and contact data belonging to other accounts on the same server.

CVE-2026-87900 affects WP Toolkit’s database-creation utility and can allow an authenticated cPanel user to alter databases owned by other accounts, breaking tenant isolation.

The issues affect cPanel and WHM version 120 and later, while the database vulnerability also affects WP Toolkit 6.11.2-10794 and earlier. The report says researchers have not confirmed exploitation in the wild and that no public proof-of-concept code is available. Administrators should upgrade cPanel and WHM to version 11.138.0.8 or later, and update WP Toolkit to version 6.11.3 using the official installer script. The vendor said the cPanel update also repairs storage permissions on existing accounts.

View full article

Article by CyberSIXT