New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts
cPanel patched a root privilege escalation and cross-tenant flaws in calendars, contacts, and WordPress databases.
cPanel's September 22, 2026 release fixes three tenant-isolation flaws in cPanel and WHM 120 and later. CVE-2026-68490 is an incorrect-permissions bug in CalDAV and CardDAV that lets a local user read, but not modify, other accounts' calendars and contacts. CVE-2026-87899 lets any authenticated cPanel user execute code as root, and CVE-2026-87900 in WP Toolkit through 6.11.2-10794 lets a user alter other accounts' databases. Fixed builds are 11.134.0.57, 11.136.0.41, 11.138.0.8, WP Squared 11.138.1.11 or newer, and WP Toolkit 6.11.3 or later; no exploitation is reported.
- CVE-2026-68490 lets a local user read other accounts' calendars and contacts.
- CVE-2026-87899 lets any authenticated cPanel user execute code as root.
- CVE-2026-87900 lets a user modify databases owned by other WP Toolkit accounts.
- Fixes are cPanel/WHM 11.134.0.57, 11.136.0.41, 11.138.0.8 and WP Squared 11.138.1.11+.
- WP Toolkit must be upgraded separately to version 6.11.3 or later.
Vulnerabilities mentionedAll →
- CVE-2026-656389.2—Unauthenticated shell command injection in ConfigServer Security & Firewall (CSF)published · ConfigServer Security & Firewall (CSF)
- CVE-2026-656438.7<1%Authenticated eval injection in cPanel enables root code executionpublished · cPanel
Full article587 words · extracted from cybersecuritynews.com · click to collapse
cPanel has patched three newly disclosed security vulnerabilities that threaten tenant isolation on shared-hosting servers, including a permissions flaw that exposes other users’ calendars and contacts.
The September 22, 2026, security release addresses CVE-2026-68490 alongside a root privilege-escalation bug and a WP Toolkit cross-account database vulnerability, making immediate updates essential for hosting providers and server administrators.
cPanel Vulnerability
Tracked as CVE-2026-68490, the primary vulnerability stems from incorrect permissions in cPanel’s CalDAV and CardDAV functionality. A local user with access to the same server could exploit the weakness to read calendar events and contact information belonging to other cPanel accounts.
The flaw breaks a key security boundary in multi-tenant environments, where customers expect their account data to remain isolated.
Exploitation is limited to reading exposed records: the attacker cannot modify calendars or address books through this flaw, and successful abuse does not provide root access.
Nevertheless, leaked appointments and contact details may reveal names, email addresses, business relationships, meeting schedules, or other information useful for phishing and social-engineering attacks. Security researcher Ali Mustafa, known as rz1027, responsibly disclosed the issue to cPanel.
For shared hosts, even read-only exposure is significant because one legitimate tenant could collect private information from unrelated customers without permission.
According to the security advisory published by cPanel, CVE-2026-68490 affects cPanel and WHM versions 120 and later. Fixed builds are 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11 or newer.
Applying the update corrects permissions for newly created calendar and address-book storage while repairing unsafe permissions on existing accounts.
The same release fixes CVE-2026-87899, a substantially more dangerous vulnerability in CalDAV and CardDAV. Any authenticated cPanel account holder could escalate privileges
and execute code as root, potentially gaining complete control of the underlying server. It affects version 120 and later and is resolved by the same cPanel, WHM, and WP Squared builds listed for CVE-2026-68490.
CVE-2026-87900 affects database-creation command handling in WP Toolkit. A logged-in cPanel user could modify databases owned by other accounts, creating a serious cross-tenant integrity risk for WordPress hosting.
WP Toolkit 6.11.2-10794 and earlier are vulnerable; administrators must upgrade the separately packaged wp-toolkit-cpanel component to version 6.11.3 or later.
Administrators should update cPanel and WHM through “Home / cPanel / Upgrade to Latest Version” in WHM or run /usr/local/cpanel/scripts/upcp –force as root. WP Toolkit requires its own upgrade to 6.11.3 or later.
Teams should verify installed versions after deployment and examine account, database, calendar, and address-book activity for unexplained cross-user access.
Providers should prioritize public, multi-user systems and confirm that automatic update policies have not left individual nodes behind.
The disclosures continue a notable run of cPanel ecosystem flaws. Recent Cyber Security News coverage includes CVE-2026-65638, an unauthenticated command-injection issue in ConfigServer Security & Firewall’s optional MESSENGER service; CVE-2026-67401, an EmailTrack SQL injection leading to root code execution; and CVE-2026-65643, a domain-parking flaw allowing authenticated users to create arbitrary files and obtain root control.
A separate LiteSpeed Enterprise vulnerability affecting versions before 6.3.7 could let low-privileged shared-hosting users bypass tenant isolation and gain root access.
The vulnerabilities covered are CVE-2026-68490, CVE-2026-87899, CVE-2026-87900, CVE-2026-65638, CVE-2026-67401, CVE-2026-65643, and the LiteSpeed Enterprise flaw fixed in version 6.3.7.
Prompt patching is critical because a single compromised hosting account can expose neighboring tenants or, in the most severe cases, the entire server.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.