CVE Tools
Back to feed
Patch released cPanel & WHM rce WP Toolkit cPanel web-app

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

cPanel has fixed CVE-2026-87899 in CalDAV and CardDAV, which could allow an authenticated hosting account to execute code as root on cPanel & WHM version 120 and later. The updates also address CVE-2026-68490, exposing other accounts' calendar and contact data, and CVE-2026-87900 in WP Toolkit 6.11.2-10794 and older, which permits cross-account database changes; administrators should update cPanel & WHM to 11.134.0.57, 11.136.0.41, 11.138.0.8, or later, and WP Toolkit to 6.11.3 or later.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store