New cPanel Vulnerabilities Allow Hosting Account Access To Critical Server Functions

New cPanel Vulnerabilities Allow Hosting Account Access To Critical Server Functions

cPanel has released security updates addressing three vulnerabilities affecting its hosting management platform, including a critical flaw that could allow a user with a cPanel hosting account to execute code with elevated privileges on the server. The most serious issue, tracked as CVE 2026 87899, affects cPanel’s CalDAV and CardDAV service and could allow a logged in account holder to run code with root level permissions under specific conditions. cPanel disclosed the vulnerabilities on September 22 and provided fixed versions for affected components. The company also addressed a separate issue in WP Toolkit that could allow account holders to modify databases belonging to other users, along with another CalDAV and CardDAV issue involving unauthorized access to calendar and contact information.

The critical vulnerability CVE 2026 87899 affects cPanel and WHM version 120 and later when the affected CalDAV and CardDAV functionality is present. According to cPanel, the flaw requires only a valid hosting account, meaning users on shared hosting environments could potentially pose a risk if systems are not updated. The issue is particularly relevant for hosting providers that offer multiple customer accounts on the same server, as a single compromised account could potentially impact the wider hosting environment. cPanel has released fixes through updated builds including versions 11.134.0.57 or later, 11.136.0.41 or later, 11.138.0.8 or later, and WP Squared 11.138.1.11 or later. The company has not reported confirmed exploitation of the vulnerability, and the issue was not listed in CISA’s Known Exploited Vulnerabilities catalog at the time of reporting.

Another vulnerability, identified as CVE 2026 87900, affects WP Toolkit, a plugin used for managing WordPress websites through hosting platforms. According to cPanel, a logged in cPanel user using affected versions of WP Toolkit could perform database modifications involving other accounts. The issue affects WP Toolkit versions 6.11.2 10794 and older, with the company releasing version 6.11.3 as the fix. cPanel has not disclosed the full extent of possible database changes or whether information from other accounts could also be accessed. WP Toolkit is also available for Plesk, another hosting control panel developed by WebPros, although cPanel has not confirmed whether the Plesk version is affected by the same issue.

The third vulnerability, CVE 2026 68490, also affects the CalDAV and CardDAV service and could allow a local user on the server to access calendar events and contact information belonging to other accounts. Unlike the root level issue, cPanel stated that this vulnerability does not allow users to modify information or gain elevated privileges. The company credited security researcher Ali Mustafa, known online as rz1027, for reporting all three vulnerabilities. The disclosure follows other security fixes involving cPanel and Plesk products in recent weeks, including previous issues affecting hosting account privileges and server management functions.

cPanel has advised customers to update affected systems to the latest available versions. For cPanel and WHM users, updates can be applied through the WHM upgrade interface or by using the official update process provided by cPanel. The update also restores calendar and contact permissions for existing accounts affected by the CalDAV and CardDAV issues. WP Toolkit users should update the plugin to version 6.11.3 or later through the available package update process. cPanel has not provided temporary workarounds for systems that cannot immediately install updates. Organizations managing hosting infrastructure are encouraged to review affected configurations, apply security patches, and monitor systems for unusual account activity as part of broader server security practices.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment