• Friday, September 25, 2026

cPanel has published fixes for three vulnerabilities affecting CalDAV/CardDAV and WP Toolkit. Administrators should update the control-panel build, confirm WP Toolkit 6.11.3 or later, and verify both versions.

Three cPanel security fixes require two version checks

cPanel published three security advisories on September 22, 2026. The most consequential issue can allow an authenticated cPanel account holder to escalate privileges and execute code as root.

Two related fixes address cross-account access to calendar and contact information and cross-account database modification through WP Toolkit.

The practical response has two parts: update cPanel & WHM or WP2 to the patched build for its release line, and confirm WP Toolkit is version 6.11.3 or later where it is installed.

CVE-2026-87899: authenticated account to root

An authenticated cPanel account holder can escalate privileges through the CalDAV and CardDAV functionality. cPanel says successful exploitation leads to code execution as the `root` user, giving the attacker full control of the server.

This matters on shared hosting because the starting point is an ordinary authenticated hosting account rather than a WHM administrator account. A failure at that boundary can turn one account-level incident into a server-wide incident.

The advisory does not say that every authenticated account has been exploited or that the issue is remotely exploitable without credentials.

CVE-2026-68490: cross-account calendar and contact disclosure

A permissions issue could allow a local user on the same server to read calendar events and contacts belonging to other accounts.

cPanel states that this issue does not allow the attacker to modify that data and does not grant root access. Updating repairs permissions on existing calendar and address-book storage as well as correcting permissions for new storage.

CVE-2026-87900: WP Toolkit cross-account database modification

The WP Toolkit issue affects database-creation command handling. An authenticated cPanel user could modify databases belonging to other accounts.

Affected versions are WP Toolkit 6.11.2-10794 and older. The fixed destination is WP Toolkit 6.11.3 or later.

This is a separate version check from the main cPanel build. A server can have a patched cPanel release while still requiring the WP Toolkit update.

Updating and verification

cPanel supports updating through WHM at Home > cPanel > Upgrade to Latest Version or from the command line:

/usr/local/cpanel/scripts/upcp --force