CVE-2026-87899

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 18 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 16 mentions (2026-09-23); latest day: 2
  • 18 total mentions across 2 days

Deep dive

Activity timeline18 mentions / 2d
0481216Mentions · 2026-09-23: 16Mentions · 2026-09-24: 209-2309-24
Referenced assets9 URLs
Full discourse18 posts
  • The Hacker News@TheHackersNews

    ‼️ ALERT: A new cPanel flaw, CVE-2026-87899, in CalDAV/CardDAV lets any logged-in cPanel account run code as root and take full control of the server. A second flaw, CVE-2026-87900 in WP Toolkit, lets authenticated users modify databases belonging to other accounts. 🔗 Learn more → https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html

    116032155742.1K
    2.4M followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CPANEL CVE-2026-87899: CALDAV/CARDDAV PATH TO ROOT ON SHARED HOSTING cPanel / WebPros published an official security advisory for CVE-2026-87899 in cPanel’s CalDAV/CardDAV stack (disclosed September 22, 2026). An authenticated cPanel account holder can escalate via CalDAV/CardDAV to code execution as root, giving full server control. The issue affects cPanel/WHM v120 or later and is especially relevant for shared hosting, where any customer account is enough — WHM admin access is not required. Fixed builds include 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and WP Squared 11.138.1.11+. ⚠️ Analyst Note: The vendor advisory does not claim known in-the-wild exploitation, and this CVE was not listed in CISA KEV as of our check. Treat as a high-priority patching item for hosting providers and anyone running affected cPanel/WHM builds. Credit: Ali Mustafa (rz1027). Related same-day official cPanel CalDAV/CardDAV and WP Toolkit advisories exist (CVE-2026-68490, CVE-2026-87900); this post focuses on the root-escalation path. Primary: https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026 #DDW #cPanel #CVE202687899 #WebHosting #PrivilegeEscalation #RCE #ThreatIntelligence #CyberSecurity

    0201225.2K
    204.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 cPanel'de CalDAV/CardDAV işlevselliğinde iki güvenlik açığı (CVE-2026-68490, CVE-2026-87899) yamalandı. • CVE-2026-68490: Aynı sunucudaki local kullanıcıların diğer hesaplara ait takvim ve kişi verilerini okumasına izin verebiliyor. • CVE-2026-87899: Kimliği doğrulanmış bir cPanel hesabının yetkisini yükselterek root olarak kod çalıştırmasına ve sunucunun tamamen ele geçirilmesine yol açabiliyor. cPanel sürümlerinizi mutlaka güncelleyin! Örneğin: cPanel 136 kullanıcıları için: 11.136.0.41+ cPanel 138 kullanıcıları için: 11.138.0.8+ ... https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026 https://support.cpanel.net/hc/en-us/articles/43502940099991-Security-CVE-2026-68490-Vulnerability-in-cPanel-s-CalDAV-CardDAV-Functionality-September-22-2026

    020131794
    2.4K followersView on X
  • orbitant@orbitant

    Root access is not supposed to be a hosting feature, but cPanel just admitted it is one right now. On September 22 the company disclosed a flaw in its CalDAV and CardDAV service (CVE-2026-87899, CVE-2026-68490) that lets anyone with a plain cPanel account run code as root and take full control of the server. No privilege escalation tricks needed, just a login. That matters for every AI agent or bot currently deployed on shared cPanel boxes, which is a large share of budget cloud hosting. If an agent's process, cron job, or API key sits on a server where another tenant can become root, isolation between accounts stops being real. A second bug, in the WP Toolkit plugin used to manage WordPress sites (CVE-2026-87900), lets one account modify databases belonging to another, no root needed for that one. Fixes exist. cPanel & WHM users patch through WHM's Upgrade to Latest Version or by running upcp --force as root, which also repairs calendar permissions on existing accounts. WP Toolkit needs a separate manual update to 6.11.3 via its installer script, since it ships as its own package. There is no workaround for servers that can't update yet, and no public proof-of-concept has surfaced as of September 23. Any pipeline that spins up agents on shared or low-cost VPS hosting should confirm the provider has actually pushed these builds, not just scheduled them. A hosting bill is cheap. Rebuilding trust in a compromised host is not.

    0006080
    3.5K followersView on X
  • Cyberattaque.org@CyberattaqueOrg

    🚨 Si vous utilisez #cPanel, mettez à jour rapidement. Les hébergements mutualisés sont particulièrement exposés. La faille critique #CVE-2026-87899 permet à un simple utilisateur authentifié d’obtenir les privilèges root et potentiellement de prendre le contrôle complet du serveur. https://www.cyberattaque.org/cve-2026-87899-cpanel-faille/

    1101061
    161 followersView on X
  • Justin Middler@JustinMiddler

    cPanel patched critical CalDAV/CardDAV RCE: any hosting account can run code as root (CVE-2026-87899). Also WP Toolkit cross-account DB changes (CVE-2026-87900) and a calendar data leak. Fixed builds out for 134/136/138. https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html

    1001042
    75 followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX

    🚨 ONE cPANEL ACCOUNT COULD TAKE OVER THE ENTIRE HOSTING SERVER cPanel has patched a serious flaw in its CalDAV/CardDAV service: CVE-2026-87899 A logged-in cPanel customer can potentially: Normal hosting account ↓ Trigger vulnerable service ↓ Execute code as ROOT ↓ Take full control of shared server That's especially dangerous on shared hosting. One customer account may coexist with: → Hundreds of websites → Databases → Email accounts → Credentials → Customer files Two more flaws were patched alongside it. CVE-2026-87900 allows one cPanel account to modify databases belonging to other accounts through WP Toolkit. CVE-2026-68490 can expose other users' calendar and contact data. No active exploitation has been reported. But hosting providers should not treat this like a normal application patch. CyberSignal insight: Multi-tenant systems live or die by isolation. When one tenant becomes root, multi-tenancy stops existing. Source: cPanel · The Hacker News #Cybersecurity #WebHosting #Linux

    0101036
    226 followersView on X
  • SHELLCODE@sh3ll_c0d3

    🔓 Linux ROOT on shared hosting via cPanel (CVE-2026-87899)! CalDAV path traversal & symlink race condition lets any unprivileged tenant hijack https://ld.so.preload for full root. 👉 Full exploit analysis: https://sh3llc0d3.com/blog/breaking-shared-hosting-inside-cpanels-caldav-root-zero-day-cve-2026-87899/ #sh3llc0d3 #shellcode

    0001056
    83 followersView on X
  • SPARQIO@sparqio

    Any AI agent or automated workload running on a shared cPanel server has a new root-level risk to close out this week. cPanel disclosed three flaws on September 22. The worst, CVE-2026-87899 in the CalDAV/CardDAV service, lets any standard hosting account run code as root and take full control of the server. No special privileges required, just a working account login. A second flaw, CVE-2026-87900 in WP Toolkit, lets one account holder modify databases belonging to other accounts on the same server. A third, CVE-2026-68490, lets a local user read other accounts' calendar and contact data, without write access or root. None of the three has a known workaround. No exploitation has been reported, and none appears in CISA's Known Exploited Vulnerabilities catalog as of September 23. For cPanel & WHM: go to Home / cPanel / Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root. For WP Toolkit: update to 6.11.3 or later with the installer script from http://wp-toolkit.plesk.com. Automatic updates are not confirmed to cover this version, so run it manually. Any agent, script, or pipeline provisioning or managing sites on cPanel infrastructure should verify the build number before its next deployment cycle, not after.

    0001047
    33 followersView on X
  • Anthony Bahn@HoustonIntrove1

    @TheHackersNews I used to shrug at CalDAV on shared cPanel. Then a tenant account turns into root via CVE-2026-87899. That changes the threat model for every reseller host I touch.

    00010271
    31 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    cPanel patched critical cPanel security vulnerabilities including CVE-2026-87899. Update cPanel and WP Toolkit now to prevent privilege escalation. #cPanel #WHM #WPToolkit #PrivilegeEscalation #Cybersecurity #Infosec #CVE202687899 https://securityonline.info/cpanel-security-vulnerabilities-patch/

    00000260
    13.0K followersView on X
  • NeoTeo.com@NeoteoCom

    CVE-2026-87899 en cPanel deja a cualquier cuenta ejecutar código como root vía CalDAV/CardDAV. https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html

    00000134
    15.9K followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — cPanel ROOT PRIVILEGE ESCALATION DATE: September 22, 2026 CONFIRMED BY: cPanel PRODUCT: cPanel & WHM CalDAV/CardDAV CVE: CVE-2026-87899 IMPACT: An authenticated cPanel account holder can escalate privileges and execute code as root, resulting in full server compromise. AFFECTED VERSIONS: cPanel/WHM v120+ before 11.134.0.57, 11.136.0.41, or 11.138.0.8 on the respective supported branches; WP2 before 11.138.1.11. EXPLOITATION STATUS: No confirmed in-the-wild exploitation found in the reviewed sources. URGENT ACTION: Update cPanel/WHM immediately to the patched build for your release branch. SOURCE: https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026 #CyberSecurity #InfoSec #ThreatIntel #cPanel #CVE #PrivilegeEscalation #Vulnerability #SecOps

    0000041
    221 followersView on X
  • Christopher Elliott@Chris_L_Elliott

    @TheHackersNews CalDAV/CardDAV as a root path (CVE-2026-87899) is shared-hosting classic: tenant auth ≠ host boundary. Pair the WP Toolkit cross-account DB issue (CVE-2026-87900) and you’ve got lateral move without needing a public RCE. Patch trains matter more than “we don’t expose calendars.”

    0000057
    60 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis reveals attackers exploiting CVE-2026-87899 in cPanel's CalDAV service to escalate from basic hosting accounts to root privileges. With full server control, they pivoted laterally across shared hosting environments, compromising multiple customer accounts. Runtime segmentation helps contain such post-compromise activity. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cpanel-cve-2026-87899-87900-68490-caldav-cardDAV-wp-toolkit-root-privilege-escalation

    0000047
    2.0K followersView on X
  • SPIN IDG@spinidg

    cPanel has patched three vulnerabilities, including critical CVE-2026-87899, which could allow a hosting account holder to execute code with root-level privileges under specific conditions. Read More on CSO Pakistan

    0000046
    2.0K followersView on X
  • Phylex@phylexNet

    cPanel's 22 September advisory reports a CalDAV/CardDAV flaw that lets an authenticated account gain root privileges. Hosting operators should check their release against the patched builds and update promptly. https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026

    0000026
    22 followersView on X
  • Hazem Omier@hazemomier

    CalDAV → root on shared hosting is the same failure mode as an agent tool with host reach: one tenant permission becomes machine takeover. CVE-2026-87899 / CVE-2026-87900: patch now, kill cross-account WP Toolkit paths, and treat every hosting account as a control plane until proven otherwise.

    0000035
    411 followersView on X

Explore more