cPanel CVE-2026-87899: Any Hosting Account Can Run Code as Root on Shared Servers via CalDAV Flaw

cPanel CVE-2026-87899: Any Hosting Account Can Run Code as Root on Shared Servers via CalDAV Flaw

cPanel CVE-2026-87899: Any Hosting Account Can Run Code as Root on Shared Servers via CalDAV Flaw

cPanel has fixed three vulnerabilities in its hosting control panel stack — including a flaw that lets any logged-in hosting account run code as root and take "full control of the server." The most serious of the three, CVE-2026-87899, sits in the CalDAV and CardDAV service that stores each account's calendars and contacts, and cPanel lists no requirements for exploiting it beyond having an account. On a shared server where a hosting provider sells accounts to the public, that means any customer could use it — so could anyone who steals a customer's login. The fixes shipped September 22 alongside a second flaw, CVE-2026-87900, in the WP Toolkit plugin used to install and manage WordPress sites, which lets an account holder modify databases belonging to other accounts.

A third bug, CVE-2026-68490, in the same calendar-and-contacts service, lets a local user on the server read other accounts' calendar events and contacts — a smaller blast radius, but a clear tenant-isolation failure on shared infrastructure.

None of the advisories mentions exploitation in the wild, and the flaws were not in CISA's Known Exploited Vulnerabilities catalog as of September 23. For a shared-hosting provider, "not exploited yet" is a short-lived comfort: the precondition for the root flaw is a credential that gets phished every day.

Who Is Affected and What Fixes It

The calendar-service flaws affect cPanel & WHM version 120 and later, with fixed builds in the 134, 136 and 138 release lines (11.134.0.57, 11.136.0.41, 11.138.0.8 or later, plus WP Squared 11.138.1.11). The WP Toolkit flaw affects version 6.11.2-10794 and older and is fixed in 6.11.3. WP Toolkit is also available for Plesk — the other hosting control panel from the same company, WebPros — and cPanel has not said whether the Plesk version is affected.

All three flaws were reported by researcher Ali Mustafa, who goes by rz1027. Vendor advisories and CVE records credit him with at least seven cPanel and Plesk flaws disclosed since August 27, including a September 8 flaw in cPanel's EmailTrack feature that let an account with mail privileges run code as root, and two Plesk flaws fixed September 10 that could each let a customer take over the whole server.

What Should You Do?

  1. Update cPanel & WHM now. In WHM, go to Home / cPanel / Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root. The update also repairs calendar and contact permissions for existing accounts.
  2. Update WP Toolkit to 6.11.3 or later — it ships as its own package (wp-toolkit-cpanel) with its own update; cPanel publishes a manual installer command for the exact version.
  3. If you run Plesk with WP Toolkit, verify the plugin's version with the vendor before assuming the cross-account database flaw doesn't apply.
  4. Check for cross-account tampering after patching. The fixes close the holes but don't announce what happened through them — review database change logs and look for calendar/contact data accessed by the wrong account.
  5. Treat every tenant as an attacker on shared infrastructure. Audit which per-account features (CalDAV, mail tools, plugin managers) expose privileged paths, and disable the ones your customers don't use.

The WAF Angle

The root flaw is the shared-hosting nightmare scenario in one sentence: a tenant-to-root escape with no exploitation preconditions. It joins a rough month for web stacks — WordPress sites have been absorbing chained attacks from comment XSS to theme-install abuse since the Click2Shell disclosure — and it lands on the same kind of server. The defensive lesson is about trust boundaries: once a control panel hands each tenant a small API surface (CalDAV, mail, database tools), every one of those surfaces is a privilege-escalation candidate, and a WAF that can see per-account request patterns is well placed to notice one account probing features it has never used before. For providers, anomaly-alerting on tenant accounts is the control that catches the attacker with a phished password — the one precondition this flaw actually requires.

Sources