Control-panel vendor cPanel has patched a security flaw that allowed any authenticated user to escalate privileges to root level on shared hosting servers. The vulnerability, tracked internally as CVE-2026-87899, was disclosed alongside two other issues in advisories published on September 22, 2026.
What was fixed
The most severe flaw resided in cPanel’s CalDAV and CardDAV functionality, which has been handled by the cpdavd service since version 120. An attacker with a valid cPanel account could exploit the flaw to execute arbitrary code as the root user, gaining full control over the server. No additional conditions or permissions were required beyond holding an account, meaning any customer on a shared server could potentially compromise the entire machine.
The fix was delivered in builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 for standard cPanel and WHM deployments, and 11.138.1.11 for WP Squared. These updates also addressed a separate issue in the same service that allowed users to read calendars and contacts belonging to other accounts, though not modify them or escalate privileges further.
A third vulnerability, unrelated to cpdavd, affected WP Toolkit, a separate package that ships with cPanel. The flaw allowed authenticated users to modify databases owned by other accounts. The advisory did not specify whether data could also be read or if access to WP Toolkit itself was required. The fix for this issue was delivered in WP Toolkit version 6.11.3, which must be applied separately from the cPanel updates.
- Flaw CVE-2026-87899 allowed root access from any cPanel account
- Patched builds: 11.134.0.57, 11.136.0.41, 11.138.0.8, and 11.138.1.11 (WP Squared)
- WP Toolkit fix (6.11.3) requires separate installation
- No CVSS score or CVE record published as of September 24, 2026
- No temporary mitigation provided
Broader context
The September 22 advisories mark the second targeted security release for cPanel’s 134 and 136 update lines in a two-week span. The first, issued on September 8, addressed a flaw in the EmailTrack feature. A third build, released on September 10, was also labeled as security-related but included routine fixes alongside hardening measures.
During the same period, Plesk, another control-panel product under the WebPros umbrella, patched two critical vulnerabilities in its Backup Manager. Both flaws, reported by the same researcher, allowed authenticated users to gain root access. One involved a symlink race during restores, while the other permitted arbitrary file writes as root. These were fixed in Plesk for Linux versions 18.0.80.7 and 18.0.79.11. Plesk for Windows was unaffected.
All four vulnerabilities—two in cPanel and two in Plesk—were reported by security researcher Ali Mustafa, working alone or with a collaborator known as abed1526. None of the advisories mentioned evidence of active exploitation, and no severity scores or CVE records were available as of September 24.
What operators should do
Shared-hosting providers and administrators running cPanel or Plesk should apply the updates immediately. For cPanel, this means upgrading to one of the patched builds for the 134, 136, or 138 lines, depending on the deployment. WP Toolkit users must also run the separate installer for version 6.11.3, as the cPanel update does not cover it. Plesk users should upgrade to 18.0.80.7 or 18.0.79.11 for Linux.
- Servers running cPanel 120 or later are affected; earlier versions are not
- WP Toolkit updates are not automatic—manual installation is required
- No workaround exists; patching is the only remediation
The lack of CVSS scores or published CVE records leaves administrators with little guidance on prioritization. However, the potential for full server compromise from a low-privilege account makes these updates critical for any environment where untrusted users have cPanel or Plesk access.
Automated pipeline · Security
Synthesized from 1 industry feed on 24 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story New cPanel privilege escalation vulnerability not previously reported.
- Checking for duplicates — New story pre_write:; No existing article covers this specific cPanel root escalation vulnerability.
- Writing the article — Draft created article_id=595 slug=cpanel-patches-root-escalation-from-hosting-accounts
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states the advisories were published 'on September 22, 2026,' which is correct per the source. However, the source does not explicitly state the advisories were published at a specific time on September 22, so the phrasing is acceptable but should not imply a precise timestamp.
- Quote integrity: No blockquotes are used in the draft, so this check is not applicable. However, the draft does not include any verbatim quotes from the source, which is compliant with the style guide.
- No copied phrasing: The draft avoids direct copying of phrasing from the source, but some technical terms (e.g., 'CalDAV and CardDAV functionality,' 'cpdavd service') are unavoidably similar due to their specificity. This is acceptable.
- Style compliance: The draft adheres to the structure and tone requirements. However, the 'Key facts' block includes 'No CVSS score or CVE record published as of September 24, 2026,' which is correct but could be phrased more concisely (e.g., 'No CVSS score or CVE record published').
- Sanity: The headline, standfirst, and body are consistent, and the category ('vulnerabilities') is appropriate. No half-finished sentences or JSON artifacts are present.
- Audience relevance and notability: The story is highly relevant to hosting professionals, with clear actionable impact. The subject (cPanel) is industry-notable, and the vulnerability is severe.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image reused image #27
- Linking related stories — Linked 3 relations from 330 candidates
- Publishing — Published cpanel-patches-root-escalation-from-hosting-accounts
- Mastodon — Posted https://mstdn.social/@hostingpaper/117325403375468933




Discussion · coming soon
Be the first to join the thread when community discussion launches.