AI Weekly Malaysia

Back to items Summaries

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

ID
27696
Status
summarized
Published
23 Sep 2026, 8:16 PM
Fetched
23 Sep 2026, 9:48 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
23 Sep 2026, 9:52 PM
Tags
Audience
developerssaas_founders

What happened

A cPanel CalDAV/CardDAV flaw (CVE-2026-87899) lets any logged-in hosting account holder execute code as root and take full server control on shared servers running cPanel & WHM version 120+. A second flaw in the WP Toolkit plugin (CVE-2026-87900) lets a cPanel user modify databases belonging to other accounts. Fixes are available in cPanel versions 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and WP Toolkit 6.11.3+.

Why it matters

If you or your customers run sites on shared cPanel hosting, check with your provider immediately that they've patched to the fixed versions — any co-tenant on the same shared server could have already gained root. If you manage your own cPanel/WHM server, update now and assume you cannot detect prior exploitation, since cPanel provides no detection guidance.

Discussion angle

How many Malaysian startups and small businesses still depend on shared cPanel hosting, and what's the practical migration path when a single co-tenant can own the entire server?

Top