Vulnerability
Published 2026-09-22
Verified 2026-09-23

cPanel CalDAV/CardDAV CVE-2026-87899: authenticated hosting account → root RCE (fix 11.134.0.57 / 11.136.0.41 / 11.138.0.8)

cPanel support advisory (22 September 2026) documents CVE-2026-87899: an authenticated cPanel account holder can escalate through CalDAV/CardDAV functionality to code execution as root and full server control. Affects cPanel/WHM v120 or later; patched in 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and WP Squared 11.138.1.11+. Same-day related advisories (not separate desk cards): CVE-2026-87900 (WP Toolkit ≤6.11.2-10794 — authenticated cPanel user can modify other accounts' databases; fix WP Toolkit 6.11.3+) and CVE-2026-68490 (CalDAV/CardDAV — local user can read other accounts' calendar/contacts; same cPanel/WHM patched trains; no root). Vendor advisories do not publish CVSS and do not state exploitation. Credited to Ali Mustafa (rz1027). Primary: cPanel support CVE-2026-87899; secondary: The Hacker News 23 Sep 2026.

Product
cPanel & WHM CalDAV/CardDAV (shared hosting account → root); related WP Toolkit database-creation path
Versions
CVE-2026-87899 / CVE-2026-68490: cPanel/WHM v120 or later before 11.134.0.57 / 11.136.0.41 / 11.138.0.8 (WP Squared before 11.138.1.11). CVE-2026-87900: WP Toolkit 6.11.2-10794 and older; fixed in 6.11.3+.
Exploited in Australia?
unknown
Patch to
Update cPanel/WHM to 11.134.0.57+, 11.136.0.41+, or 11.138.0.8+ (WP Squared 11.138.1.11+); update WP Toolkit to 6.11.3+ via vendor installer; prioritize shared-hosting nodes where untrusted customers hold cPanel accounts; review related advisories CVE-2026-87900 and CVE-2026-68490

Primary: cPanel Support — CVE-2026-87899 CalDAV/CardDAV authenticated root RCE (22 Sep 2026) · Vendor: cPanel — Security CVE-2026-87899 · CVE: CVE-2026-87899, CVE-2026-87900, CVE-2026-68490 · The Hacker News — cPanel CalDAV/CardDAV root + WP Toolkit (23 Sep 2026)

vulnerabilities cloud australia