Open Nav
Sign Up

Critical cPanel Flaw CVE-2026-87899 Enables Root Code Execution

cpanel_cve-2026-87899

Filip Dimitrov

September 24, 2026

A critical vulnerability in cPanel & WHM can allow an authenticated cPanel user to escalate privileges and execute arbitrary code as the root user, potentially giving an attacker complete control over an affected hosting server.

Tracked as CVE-2026-87899, the vulnerability affects cPanel’s CalDAV and CardDAV functionality and carries a CVSS 4.0 score of 9.4 (Critical). WebPros released patched versions on September 22, 2026, with the CVE formally published the following day.

CVE-2026-87899 Overview

CVE-2026-87899 is classified as CWE-250: Execution with Unnecessary Privileges. According to the official vulnerability record, the flaw allows a remote authenticated user to execute arbitrary code with root privileges.

The vulnerability exists in the CalDAV and CardDAV functionality used by cPanel to provide calendar and contact synchronization.

Beginning with cPanel & WHM version 120, WebPros moved calendar and contact management into the cpdavd service. The daemon handles access to CalDAV and CardDAV resources and exposes these services through TCP ports 2079 and 2080, with 2080 providing the SSL/TLS-protected service.

WebPros has not publicly released detailed exploitation instructions or the precise vulnerable code path. However, the company confirmed that an authenticated cPanel account holder can use the affected CalDAV/CardDAV functionality to escalate privileges and ultimately execute code as root.

This means CVE-2026-87899 should be viewed as more than a conventional privilege-escalation issue. In a shared-hosting environment, where numerous unrelated customers may have legitimate accounts on the same infrastructure, the vulnerability can convert a single low-privileged tenant into full compromise of the underlying host.

Impact

Once root access is obtained, an attacker could potentially access or modify websites belonging to other customers, steal credentials and application secrets, manipulate databases, deploy malware or web shells, create persistence mechanisms, interfere with security tooling, or use the compromised server as infrastructure for further attacks.

Affected cPanel Versions

WebPros states that cPanel & WHM version 120 and later are affected, with patched builds now available.

Product branchPatched version
cPanel & WHM 13411.134.0.57 or later
cPanel & WHM 13611.136.0.41 or later
cPanel & WHM 13811.138.0.8 or later
WP Squared11.138.1.11 or later

The CVE record identifies the vulnerable ranges as 11.120.0.0 through versions before 11.134.0.57, 11.136.0.0 through versions before 11.136.0.41, and 11.138.0.0 through versions before 11.138.0.8.

Administrators can determine the installed cPanel version from WHM or by running:

/usr/local/cpanel/cpanel -V

cPanel recommends updating through WHM → Home → cPanel → Upgrade to Latest Version, or using the upcp update script from the command line as root.

Mitigation and Recommendations

Organizations operating affected cPanel infrastructure should prioritize remediation, particularly where servers host multiple independent customers or cPanel accounts are accessible from the internet.

  • Upgrade immediately to cPanel & WHM 11.134.0.57, 11.136.0.41, 11.138.0.8, WP Squared 11.138.1.11, or a later supported release as appropriate.
  • Verify the installed version after upgrading and ensure automatic cPanel security updates are functioning correctly.
  • Review existing cPanel accounts and remove unused, unexpected or unnecessary accounts that could provide an attacker with the low-privileged access required for exploitation.
  • Enforce strong authentication and MFA wherever possible to reduce the risk of attackers obtaining legitimate cPanel credentials.
  • Review cpdavd and authentication logs for unusual source addresses, newly compromised accounts or anomalous CalDAV/CardDAV activity occurring before the server was patched.
  • If a vulnerable internet-facing system shows signs of suspicious authenticated activity, perform a broader host-level compromise assessment rather than assuming the vulnerability was not exploited.

WebPros has not published a vendor-supported workaround that provides equivalent protection to installing the fixed release. Patching therefore remains the primary remediation.

Related cPanel Vulnerabilities

CVE-2026-87899 was disclosed alongside two additional cPanel security issues.

CVE-2026-68490 also affects the CalDAV/CardDAV functionality and can allow a local user to access calendar events and contacts belonging to other accounts. CVE-2026-87900 affects WP Toolkit and can allow an authenticated cPanel user to perform unauthorized database modifications involving other hosting accounts.

The simultaneous disclosure of multiple cross-account and privilege-boundary vulnerabilities further increases the importance of ensuring cPanel components and associated tooling are fully updated rather than addressing CVE-2026-87899 in isolation.

Stay Safe. Stay Secure

OP Innovate Research Team

Under Cyber Attack?

Fill out the form and we will contact you immediately.