CVE-2026-87899

Published Sep 23, 2026

Last updated 8 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-87899 is a vulnerability found in the CalDAV and CardDAV service of cPanel & WHM. This flaw allows an authenticated user with a cPanel hosting account to execute arbitrary code with root privileges. Exploitation of this vulnerability can lead to an attacker gaining full control of the server. cPanel has released fixed versions to address this issue, specifically cPanel & WHM versions 11.134.0.57 or later, 11.136.0.41 or later, and 11.138.0.8 or later.

Description
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Source
support@hackerone.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

support@hackerone.com
CWE-250

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

12

  1. cPanel Security | cPanel Vulnerability | cPanel WHM | CVE-2026-68490 | CVE-2026-87899 | CVE-2026-87900 | Shared Hosting Security | Tenant Isolation | Cross Account Vulnerability | CalDAV Security | CardDAV Security | WP Toolkit Security | WordPress Hosting Security | Root https:/

    @pcsdf1

    24 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. cPanel patched critical CalDAV/CardDAV RCE: any hosting account can run code as root (CVE-2026-87899). Also WP Toolkit cross-account DB changes (CVE-2026-87900) and a calendar data leak. Fixed builds out for 134/136/138. https://t.co/gneTfxXl3B

    @JustinMiddler

    24 Sept 2026

    43 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. cPanelは、CalDAV/CardDAVサービスの脆弱性CVE-2026-87899により、ログイン可能なホスティングアカウントの利用者がroot権限でコードを実行し、サーバー全体を制御できると発表した。共有サーバーでは一般の顧客ア

    @yousukezan

    24 Sept 2026

    664 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. cPanelで他顧客のアカウントへのアクセスが可能になる脆弱性3件が修正された。CalDAVとCardDAVの欠陥によりroot取得可能なCVE-2026-87899、他アカウントのCalDAVとCardDAVが読み取れるCVE-2026-68490、他ユーザのデータベー

    @__kokumoto

    23 Sept 2026

    637 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  5. 🚨 #ALERT — cPanel ROOT PRIVILEGE ESCALATION DATE: September 22, 2026 CONFIRMED BY: cPanel PRODUCT: cPanel & WHM CalDAV/CardDAV CVE: CVE-2026-87899 IMPACT: An authenticated cPanel account holder can escalate privileges and execute code as root, resulting in full server

    @Python_s_

    23 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CPANEL CVE-2026-87899: CALDAV/CARDDAV PATH TO ROOT ON SHARED HOSTING cPanel / WebPros published an official security advisory for CVE-2026-87899 in cPanel’s CalDAV/CardDAV stack (disclosed September 22, 2026). An authenticated cPanel account holder can escalate via

    @DailyDarkWeb

    23 Sept 2026

    5147 Impressions

    2 Retweets

    12 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. 🔴 cPanel'de CalDAV/CardDAV işlevselliğinde iki güvenlik açığı (CVE-2026-68490, CVE-2026-87899) yamalandı. • CVE-2026-68490: Aynı sunucudaki local kullanıcıların diğer hesaplara ait takvim ve kişi verilerini okumasına izin verebiliyor. • CVE-2026-87899: Kim

    @ridvanyagli

    23 Sept 2026

    714 Impressions

    2 Retweets

    11 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.