New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
PatchcPanel & WHMWP ToolkitOur summary
cPanel has fixed CVE-2026-87899 in CalDAV and CardDAV, which could allow an authenticated hosting account to execute code as root on cPanel & WHM version 120 and later. The updates also address CVE-2026-68490, exposing other accounts' calendar and contact data, and CVE-2026-87900 in WP Toolkit 6.11.2-10794 and older, which permits cross-account database changes; administrators should update cPanel & WHM to 11.134.0.57, 11.136.0.41, 11.138.0.8, or later, and WP Toolkit to 6.11.3 or later.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.