One cPanel account can own the whole server — patch today

By George Bailey   Published: 09/25/26   3 min read

On a shared hosting server, your site’s neighbors are strangers with logins. A new cPanel bug lets any one of them run code as root, and root means every site, mailbox, and database on that box.

Hosts need to update before the weekend. Everyone else should ask their host whether they have.

On shared hosting, your neighbor’s login can become the whole server.

What happened

On September 22, cPanel disclosed CVE-2026-87899, a flaw in its CalDAV and CardDAV service, which stores each account’s calendars and contacts. It lets a logged-in account holder execute code as root and take “full control of the server.” cPanel lists no requirement other than having an account. It affects cPanel & WHM version 120 and later.

Two companion bugs shipped the same day:

All three are credited to researcher Ali Mustafa (rz1027).

Why it matters

Shared hosting sells accounts to the public. On an unpatched server, any customer, or anyone who phished one customer’s login, can become root and reach every other tenant.

No exploitation has been reported, and the bugs weren’t in CISA’s KEV catalog as of September 23. But cPanel offers no workaround, so patching is the only control. It’s the second hosting-panel escalation this month after the Acronis backup plugin for cPanel, and it lands the same week as the exploited WordPress Core bug many of these servers also host.

What to do first

  1. Update cPanel & WHM to 11.134.0.57, 11.136.0.41, or 11.138.0.8 or later (WP Squared: 11.138.1.11+). In WHM: Home › cPanel › Upgrade to Latest Version, or run /usr/local/cpanel/scripts/upcp --force as root.
  2. Update WP Toolkit to 6.11.3 or later with cPanel’s installer command. cPanel hasn’t said whether auto-update will pick it up.
  3. Move off older lines. Servers on 120–133 need a fixed release line; cPanel lists fixed builds only for 134, 136, 138 and WP Squared.
  4. Customers on shared hosting: ask your provider to confirm both updates are done.

Forward this

If any of our sites live on cPanel hosting: ask the host (or our server admin) to confirm cPanel is on 11.134.0.57 / 11.136.0.41 / 11.138.0.8+ and WP Toolkit is on 6.11.3+.

Details

Hunt / verify

Slack paste: cPanel → 11.134.0.57 / 11.136.0.41 / 11.138.0.8+ and WP Toolkit 6.11.3+; no workaround; shared-hosting customers ask the host.

Hosting and web-panel fixes like this land in the CyberExperts Daily Brief each weekday morning, so you know what to ask your host.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.