New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts
cPanel patched a root privilege escalation and cross-tenant flaws in calendars, contacts, and WordPress databases.
cPanel's September 22, 2026 release fixes three tenant-isolation flaws in cPanel and WHM 120 and later. CVE-2026-68490 is an incorrect-permissions bug in CalDAV and CardDAV that lets a local user read, but not modify, other accounts' calendars and contacts. CVE-2026-87899 lets any authenticated cPanel user execute code as root, and CVE-2026-87900 in WP Toolkit through 6.11.2-10794 lets a user alter other accounts' databases. Fixed builds are 11.134.0.57, 11.136.0.41, 11.138.0.8, WP Squared 11.138.1.11 or newer, and WP Toolkit 6.11.3 or later; no exploitation is reported.