
🚨 CPANEL CVE-2026-87899: CALDAV/CARDDAV PATH TO ROOT ON SHARED HOSTING cPanel / WebPros published an official security advisory for CVE-2026-87899 in cPanel’s CalDAV/CardDAV stack (disclosed September 22, 2026). An authenticated cPanel account holder can escalate via CalDAV/CardDAV to code execution as root, giving full server control. The issue affects cPanel/WHM v120 or later and is especially relevant for shared hosting, where any customer account is enough — WHM admin access is not required. Fixed builds include 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and WP Squared 11.138.1.11+. ⚠️ Analyst Note: The vendor advisory does not claim known in-the-wild exploitation, and this CVE was not listed in CISA KEV as of our check. Treat as a high-priority patching item for hosting providers and anyone running affected cPanel/WHM builds. Credit: Ali Mustafa (rz1027). Related same-day official cPanel CalDAV/CardDAV and WP Toolkit advisories exist (CVE-2026-68490, CVE-2026-87900); this post focuses on the root-escalation path. Primary: https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026 #DDW #cPanel #CVE202687899 #WebHosting #PrivilegeEscalation #RCE #ThreatIntelligence #CyberSecurity




