New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
- ID
- 27696
- Status
- summarized
- Published
- 23 Sep 2026, 8:16 PM
- Fetched
- 23 Sep 2026, 9:48 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.0
- Created
- 23 Sep 2026, 9:52 PM
- Tags
- Audience
- developerssaas_founders
What happened
A cPanel CalDAV/CardDAV flaw (CVE-2026-87899) lets any logged-in hosting account holder execute code as root and take full server control on shared servers running cPanel & WHM version 120+. A second flaw in the WP Toolkit plugin (CVE-2026-87900) lets a cPanel user modify databases belonging to other accounts. Fixes are available in cPanel versions 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and WP Toolkit 6.11.3+.
Why it matters
If you or your customers run sites on shared cPanel hosting, check with your provider immediately that they've patched to the fixed versions — any co-tenant on the same shared server could have already gained root. If you manage your own cPanel/WHM server, update now and assume you cannot detect prior exploitation, since cPanel provides no detection guidance.
Discussion angle
How many Malaysian startups and small businesses still depend on shared cPanel hosting, and what's the practical migration path when a single co-tenant can own the entire server?