AI description
CVE-2026-87899 is a vulnerability found in the CalDAV and CardDAV service of cPanel & WHM. This flaw allows an authenticated user with a cPanel hosting account to execute arbitrary code with root privileges. Exploitation of this vulnerability can lead to an attacker gaining full control of the server. cPanel has released fixed versions to address this issue, specifically cPanel & WHM versions 11.134.0.57 or later, 11.136.0.41 or later, and 11.138.0.8 or later.
- Description
- Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
- Source
- support@hackerone.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- support@hackerone.com
- CWE-250
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
12
cPanel Security | cPanel Vulnerability | cPanel WHM | CVE-2026-68490 | CVE-2026-87899 | CVE-2026-87900 | Shared Hosting Security | Tenant Isolation | Cross Account Vulnerability | CalDAV Security | CardDAV Security | WP Toolkit Security | WordPress Hosting Security | Root https:/
@pcsdf1
24 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
cPanel patched critical CalDAV/CardDAV RCE: any hosting account can run code as root (CVE-2026-87899). Also WP Toolkit cross-account DB changes (CVE-2026-87900) and a calendar data leak. Fixed builds out for 134/136/138. https://t.co/gneTfxXl3B
@JustinMiddler
24 Sept 2026
43 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
cPanelは、CalDAV/CardDAVサービスの脆弱性CVE-2026-87899により、ログイン可能なホスティングアカウントの利用者がroot権限でコードを実行し、サーバー全体を制御できると発表した。共有サーバーでは一般の顧客ア
@yousukezan
24 Sept 2026
664 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
cPanelで他顧客のアカウントへのアクセスが可能になる脆弱性3件が修正された。CalDAVとCardDAVの欠陥によりroot取得可能なCVE-2026-87899、他アカウントのCalDAVとCardDAVが読み取れるCVE-2026-68490、他ユーザのデータベー
@__kokumoto
23 Sept 2026
637 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 #ALERT — cPanel ROOT PRIVILEGE ESCALATION DATE: September 22, 2026 CONFIRMED BY: cPanel PRODUCT: cPanel & WHM CalDAV/CardDAV CVE: CVE-2026-87899 IMPACT: An authenticated cPanel account holder can escalate privileges and execute code as root, resulting in full server
@Python_s_
23 Sept 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CPANEL CVE-2026-87899: CALDAV/CARDDAV PATH TO ROOT ON SHARED HOSTING cPanel / WebPros published an official security advisory for CVE-2026-87899 in cPanel’s CalDAV/CardDAV stack (disclosed September 22, 2026). An authenticated cPanel account holder can escalate via
@DailyDarkWeb
23 Sept 2026
5147 Impressions
2 Retweets
12 Likes
2 Bookmarks
0 Replies
0 Quotes
🔴 cPanel'de CalDAV/CardDAV işlevselliğinde iki güvenlik açığı (CVE-2026-68490, CVE-2026-87899) yamalandı. • CVE-2026-68490: Aynı sunucudaki local kullanıcıların diğer hesaplara ait takvim ve kişi verilerini okumasına izin verebiliyor. • CVE-2026-87899: Kim
@ridvanyagli
23 Sept 2026
714 Impressions
2 Retweets
11 Likes
0 Bookmarks
0 Replies
0 Quotes