cPanel Patches Critical Vulnerabilities Threatening Shared-Hosting Security
On September 22, 2026, cPanel released a security update addressing three critical vulnerabilities that compromise tenant isolation on shared-hosting servers. The most notable flaw, CVE-2026-68490, involves incorrect permissions in cPanel’s CalDAV and CardDAV functionality, allowing local users to access other accounts’ calendars and contacts. While exploitation is limited to read-only access, exposed data such as names, emails, and meeting schedules could fuel phishing or social-engineering attacks. The vulnerability affects cPanel and WHM versions 120 and later, with fixes available in builds 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11 or newer.
The same update resolves CVE-2026-87899, a severe privilege-escalation bug in CalDAV and CardDAV that enables authenticated users to execute code as root, potentially seizing full server control. Additionally, CVE-2026-87900 impacts WP Toolkit, where a logged-in user could modify databases belonging to other accounts, posing a cross-tenant integrity risk. WP Toolkit versions 6.11.2-10794 and earlier are vulnerable; administrators must upgrade to 6.11.3 or later.
cPanel recommends immediate updates via WHM or the command line, followed by verification of installed versions and monitoring for unauthorized cross-user access. The disclosures follow a string of recent cPanel ecosystem flaws, including CVE-2026-65638 (unauthenticated command injection), CVE-2026-67401 (SQL injection leading to root code execution), and CVE-2026-65643 (domain-parking exploit). A separate LiteSpeed Enterprise vulnerability (fixed in version 6.3.7) also allowed low-privileged users to bypass tenant isolation and gain root access. Hosting providers are urged to prioritize patching, as a single compromised account could expose neighboring tenants or the entire server.
Source: https://cybersecuritynews.com/cpanel-user-account-access-flaw/
cPanel TPRM report: https://www.rankiteo.com/company/cpanel
"id": "cpa1790180943",
"linkid": "cpanel",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Hosting providers and users of '
'cPanel/WHM, WP Toolkit, and '
'LiteSpeed Enterprise',
'industry': 'Web Hosting and Server Management',
'name': 'cPanel',
'type': 'Software Provider'}],
'attack_vector': 'Local Access',
'customer_advisories': 'Users of cPanel/WHM and WP Toolkit advised to update '
'to the latest patched versions immediately.',
'data_breach': {'personally_identifiable_information': 'Names, emails, '
'meeting schedules',
'sensitivity_of_data': 'High (PII, meeting schedules, emails)',
'type_of_data_compromised': 'Calendars, contacts, databases, '
'personally identifiable '
'information (PII)'},
'date_publicly_disclosed': '2026-09-22',
'description': 'On September 22, 2026, cPanel released a security update '
'addressing three critical vulnerabilities that compromise '
'tenant isolation on shared-hosting servers. The most notable '
'flaw, CVE-2026-68490, involves incorrect permissions in '
'cPanel’s CalDAV and CardDAV functionality, allowing local '
'users to access other accounts’ calendars and contacts. The '
'same update resolves CVE-2026-87899, a severe '
'privilege-escalation bug in CalDAV and CardDAV enabling '
'authenticated users to execute code as root, and '
'CVE-2026-87900, impacting WP Toolkit, where a logged-in user '
'could modify databases belonging to other accounts.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'tenant isolation failures',
'data_compromised': 'Names, emails, meeting schedules, calendars, '
'contacts, databases',
'identity_theft_risk': 'Phishing or social-engineering attacks due '
'to exposed PII',
'operational_impact': 'Potential full server control, cross-tenant '
'integrity risk, unauthorized access to '
"other accounts' data",
'systems_affected': 'Shared-hosting servers running cPanel and WHM '
'versions 120 and later, WP Toolkit versions '
'6.11.2-10794 and earlier'},
'lessons_learned': 'Importance of tenant isolation in shared-hosting '
'environments, need for prompt patching of critical '
'vulnerabilities, and monitoring for cross-tenant access '
'risks.',
'post_incident_analysis': {'corrective_actions': 'Patching vulnerabilities, '
'verifying installed '
'versions, and enhancing '
'monitoring for cross-tenant '
'access',
'root_causes': 'Incorrect permissions in '
'CalDAV/CardDAV, '
'privilege-escalation bug, and WP '
'Toolkit database modification '
'flaw'},
'recommendations': 'Immediately update cPanel/WHM and WP Toolkit to patched '
'versions, verify installed versions, monitor for '
'unauthorized access, and prioritize patching for hosting '
'providers.',
'references': [{'source': 'cPanel Security Update'}],
'response': {'communication_strategy': 'Security update announcement and '
'patch release',
'containment_measures': 'Immediate updates via WHM or command '
'line, verification of installed '
'versions, monitoring for unauthorized '
'cross-user access',
'enhanced_monitoring': 'Monitoring for unauthorized cross-user '
'access',
'remediation_measures': 'Patches released for cPanel/WHM (builds '
'11.134.0.57, 11.136.0.41, 11.138.0.8, '
'WP Squared 11.138.1.11 or newer) and WP '
'Toolkit (6.11.3 or later)'},
'stakeholder_advisories': 'Hosting providers urged to prioritize patching as '
'a single compromised account could expose '
'neighboring tenants or the entire server.',
'title': 'cPanel Patches Critical Vulnerabilities Threatening Shared-Hosting '
'Security',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': ['CVE-2026-68490',
'CVE-2026-87899',
'CVE-2026-87900']}