cPanel patches flaws enabling root code execution from hosting accounts

cPanel releases fixes for three hosting security flaws
cPanel has released updates for three vulnerabilities affecting its hosting software, including CVE-2026-87899, which can allow a logged-in hosting account holder to execute code as root and take full control of a server. The flaw is in the CalDAV and CardDAV service used to store calendars and contacts, and affects cPanel & WHM version 120 and later.
The vendor lists no condition for exploiting CVE-2026-87899 beyond possession of a cPanel account. On a shared hosting system, the exposure could therefore extend to a paying customer, or to an attacker who obtains that customer's credentials. cPanel's advisory describes the outcome as root-level code execution.
Fixed releases are cPanel & WHM 11.134.0.57 or later, 11.136.0.41 or later, and 11.138.0.8 or later. WP Squared is fixed in version 11.138.1.11 or later. The update also repairs calendar and contact permissions for existing accounts.
WP Toolkit and data-access issues were fixed alongside it
A second issue, CVE-2026-87900, affects WP Toolkit versions 6.11.2-10794 and older. cPanel says a logged-in cPanel user could modify databases belonging to other accounts. The weakness is related to command handling for database creation, but the advisory does not specify which database changes are possible, whether data can be read, or whether access to WP Toolkit is required.
WP Toolkit 6.11.3 or later resolves that issue. WP Toolkit is separately packaged as wp-toolkit-cpanel, so updating cPanel & WHM alone does not necessarily update the plugin. WebPros also offers WP Toolkit for Plesk, although cPanel has not stated whether the Plesk version is affected.
The third vulnerability, CVE-2026-68490, is also in CalDAV and CardDAV. It allows a local server user to read calendar events and contacts from other accounts, but cPanel says it does not permit modification or root access. Its fixed versions match those for CVE-2026-87899.
Update priority for hosting operators
cPanel provides no temporary workaround for systems that cannot yet be updated. Administrators can update cPanel & WHM through Home / cPanel / Upgrade to Latest Version in WHM, or run /usr/local/cpanel/scripts/upcp --force as root. For WP Toolkit, cPanel specifies an update to version 6.11.3 or later through its installer command.
None of the three advisories states that exploitation has occurred or provides a method to determine whether a server was attacked before patching. The flaws were credited to researcher Ali Mustafa, known as rz1027. cPanel had also disclosed a September flaw in EmailTrack that could allow an account with mail privileges to run code as root.
For hosting providers, the practical implication is to treat these updates as urgent: validate the cPanel & WHM release line, update WP Toolkit as a separate component, and review account-access controls because a single compromised or malicious tenant account can carry server-wide consequences.

