cPanel Flaw Allows Root Access from Any Hosting Account

A critical bug in cPanel lets any user with a basic hosting account execute code as root, granting full control over the shared server infrastructure.
Key points
- A cPanel flaw allows any hosting account user to run code as root, taking full server control.
- A separate bug in WP Toolkit lets users modify databases belonging to other accounts.
- CPanel released fixes for the core system and plugin but offers no workaround for unpatched servers.
A critical security flaw in cPanel allows any user with a standard hosting account to execute code with root privileges. This vulnerability effectively grants an attacker full control over the server, bypassing the isolation measures that are supposed to keep individual customer accounts separate.
The company confirmed the issue on September 22, noting that no special permissions are required to exploit the bug. On shared hosting servers, this means any customer, or anyone who obtains a customer's login credentials, could potentially take over the entire machine.
Root access via calendar service
The primary vulnerability, identified as CVE-2026-87899, resides in cPanel's CalDAV and CardDAV service, which manages calendars and contacts. As reported by The Hacker News, this flaw allows a logged-in user to run arbitrary code as the root user. This is the most severe of the issues disclosed, as root access provides unrestricted control over the operating system and all other accounts on the server.
cPanel has released patched versions for the 11.134, 11.136, and 11.138 release lines to address this specific threat. The update also repairs calendar and contact permissions for existing accounts, mitigating a secondary flaw that allowed local users to read other accounts' private data.
Cross-account database interference
A second bug in the WP Toolkit plugin, used for managing WordPress sites, allows a user to modify databases belonging to other accounts. While the exact scope of these modifications is not fully detailed by the vendor, the ability to alter data in another user's database represents a significant breach of data integrity and isolation.
This issue, tracked as CVE-2026-87900, affects versions of WP Toolkit up to 6.11.2. It is unclear whether this vulnerability also impacts the Plesk version of the plugin, as cPanel has not specified if the same code structure is present in that alternative control panel.
Patch availability and limitations
CPanel has provided specific commands for administrators to update both the core system and the WP Toolkit plugin. However, the company offers no temporary workarounds for servers that cannot be immediately updated. This leaves a gap in security for organizations facing operational constraints that prevent immediate patch deployment.
Furthermore, none of the advisories provide a method to determine if a server was compromised before the update was applied. With no known exploitation details published, administrators must assume that any unpatched server may have already been accessed by an attacker.






