{"id":3099,"date":"2026-09-23T13:30:13","date_gmt":"2026-09-23T13:30:13","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3099"},"modified":"2026-09-23T13:30:13","modified_gmt":"2026-09-23T13:30:13","slug":"new-cpanel-flaw-lets-a-hosting-account-run-code-as-root-take-full-server-control","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3099","title":{"rendered":"New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 23, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhT5quc0dmRWhh6WOC80Gx9QoHTMYyq5srnXBXjybOKZk_qoUn1Q2nKLE9MifqCEyRIha_NFvRsyr8Nx5EyxGIREXaTb5Fh59cz4Ln8yZj9Zv7piqM49wmm7rfmchW1cVlss1wn47qNypaYarZUVNHBO8rzXaYTvRMi9u1phgfXVd8OZx8_Vjxm34684BE\/s1700-nu-rw-lo-l85-e365\/cpanel-0day.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A flaw in cPanel&#8217;s <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026\" target=\"_blank\">CalDAV and CardDAV service<\/a> lets anyone with a cPanel hosting account run code as root and take \u00abfull control of the server,\u00bb the company said on September 22.<\/p>\n<p>A <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43597969409943-Security-CVE-2026-87900-Vulnerability-in-WP-Toolkit-Database-Creation-September-22-2026\" target=\"_blank\">second bug<\/a> in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.<\/p>\n<p>cPanel has released fixed versions for both, along with a fix for a <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/43502940099991-Security-CVE-2026-68490-Vulnerability-in-cPanel-s-CalDAV-CardDAV-Functionality-September-22-2026\" target=\"_blank\">third flaw<\/a> in the same service, which stores each account&#8217;s calendars and contacts. That third flaw lets a local user on the server read other accounts&#8217; calendar events and contacts, but not change them or gain root access.<\/p>\n<p>cPanel lists no requirements for the root flaw other than having an account. On a shared server where a hosting provider sells accounts to the public, that means any customer could use it. So could anyone who gets hold of a customer&#8217;s login.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The three flaws and the versions that fix them:<\/p>\n<p><a name=\"more\"\/><\/p>\n<table style=\"border-collapse: collapse; border: 1px solid rgb(217, 217, 217); width: 100%;\">\n<tbody>\n<tr>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Flaw\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Where\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        What it allows, according to cPanel\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Affected\n      <\/th>\n<th scope=\"col\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        Fixed in\n      <\/th>\n<\/tr>\n<tr>\n<th scope=\"row\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        CVE-2026-87899\n      <\/th>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        CalDAV and CardDAV\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        A logged-in account holder can run code as root\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        cPanel &amp; WHM version 120 and later\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        11.134.0.57 or later<br \/>\n        <br \/>11.136.0.41 or later<br \/>\n        <br \/>11.138.0.8 or later<br \/>\n        <br \/>WP Squared 11.138.1.11 or later\n      <\/td>\n<\/tr>\n<tr>\n<th scope=\"row\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        CVE-2026-87900\n      <\/th>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        WP Toolkit\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        A logged-in cPanel user can change databases in other accounts\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        WP Toolkit 6.11.2-10794 and older\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        WP Toolkit 6.11.3 or later\n      <\/td>\n<\/tr>\n<tr>\n<th scope=\"row\" style=\"border: 1px solid rgb(217, 217, 217); padding: 10px; text-align: left;\">\n        CVE-2026-68490\n      <\/th>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        CalDAV and CardDAV\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        A local user can read other accounts&#8217; calendar events and contacts\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        cPanel &amp; WHM version 120 and later\n      <\/td>\n<td style=\"border: 1px solid rgb(217, 217, 217); padding: 10px;\">\n        11.134.0.57 or later<br \/>\n        <br \/>11.136.0.41 or later<br \/>\n        <br \/>11.138.0.8 or later<br \/>\n        <br \/>WP Squared 11.138.1.11 or later\n      <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The WP Toolkit bug is in how the plugin handles commands that create databases. cPanel says only that a logged-in cPanel user could \u00abperform database modifications in other accounts.\u00bb<\/p>\n<p>It does not say what changes are possible, whether data from other accounts can also be read, or whether the user needs access to WP Toolkit itself.<\/p>\n<p>WP Toolkit is also available for Plesk, another hosting control panel from the same company, WebPros. cPanel has not said whether the Plesk version is affected.<\/p>\n<p>None of the three advisories mentions exploitation or gives a way to check whether a server was attacked before it was updated. The flaws were not in CISA&#8217;s Known Exploited Vulnerabilities catalog when The Hacker News checked on September 23.<\/p>\n<p>cPanel credits all three flaws to Ali Mustafa, a researcher who goes by rz1027. Vendor advisories and CVE records credit him with at least seven cPanel and Plesk flaws disclosed since August 27, three of them shared with a researcher known as abed1526.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>They include a September 8 flaw in cPanel&#8217;s EmailTrack feature that let an account with mail privileges run code as root, cPanel said at the time.<\/p>\n<p>Plesk fixed two more on September 10, in how its Backup Manager <a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation\" target=\"_blank\">restores files<\/a> and how it <a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/43248841638551-Vulnerability-in-Plesk-s-Backup-Manager-unsigned-backup-header-allows-path-traversal\" target=\"_blank\">handles backup headers<\/a>. It said each could let a customer take over the whole server.<\/p>\n<h3>How to Update<\/h3>\n<p>cPanel gives separate update instructions for cPanel &amp; WHM and for WP Toolkit. WP Toolkit is installed as <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/1500000253161-Updating-WP-Toolkit\" target=\"_blank\">its own package<\/a>, wp-toolkit-cpanel, with its own update.<\/p>\n<ul>\n<li><strong>cPanel &amp; WHM<\/strong> (CVE-2026-87899 and CVE-2026-68490): follow <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/1500004959421-How-do-I-update-cPanel-WHM\" target=\"_blank\">cPanel&#8217;s update steps<\/a>. In WHM, go to Home \/ cPanel \/ Upgrade to Latest Version, or run \/usr\/local\/cpanel\/scripts\/upcp &#8211;force as root. The update also repairs calendar and contact permissions for existing accounts.<\/li>\n<li><strong>WP Toolkit<\/strong> (CVE-2026-87900): update to version 6.11.3 or later with this command: bash &lt;(curl https:\/\/wp-toolkit.plesk.com\/cPanel\/installer.sh || wget -O &#8211; https:\/\/wp-toolkit.plesk.com\/cPanel\/installer.sh) &#8211;version 6.11.3<\/li>\n<\/ul>\n<p>The calendar flaws affect version 120 and later, but cPanel lists fixed builds only for the 134, 136, and 138 release lines and for WP Squared.<\/p>\n<p>cPanel offers no temporary workaround for servers that cannot be updated yet. For WP Toolkit, only the manual command is given, and whether automatic updates will install 6.11.3 is not stated.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Sep 23, 2026Vulnerability \/ Web Security A flaw in cPanel&#8217;s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take \u00abfull control&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3100,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[573,10,425,1465,70,753,2869,332,61,1774,518],"class_list":["post-3099","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-account","tag-code","tag-control","tag-cpanel","tag-flaw","tag-full","tag-hosting","tag-lets","tag-root","tag-run","tag-server"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3099","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3099"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3099\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3100"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3099"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3099"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}