Multiple security vulnerabilities affecting cPanel versions These cPanel security vulnerabilities impact cPanel and WHM version 120 and later have been identified in cPanel and WHM version 120 and later. These flaws allow authenticated attackers to gain root access and manipulate foreign databases, posing a significant risk to shared hosting servers worldwide.
CVE-2026-87899 (CVSS 9.8 — Critical): An attacker can escalate privileges through CalDAV and CardDAV handling by exploiting the failure of privileged background tasks to sanitize user input.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting cPanel versions These cPanel security vulnerabilities impact cPanel and WHM version 120 and later have been identified in cPanel and WHM version 120 and later. These flaws allow authenticated attackers to gain root access and manipulate foreign databases, posing a significant risk to shared hosting servers worldwide.
CVE-2026-87899 (CVSS 9.8 — Critical): An attacker can escalate privileges through CalDAV and CardDAV handling by exploiting the failure of privileged background tasks to sanitize user input.[emaillocker id="1283"]
CVE-2026-68490: A permissions issue in CalDAV and CardDAV storage exposes sensitive data, allowing a local user on the same server to access calendar and contact data belonging to other accounts.
CVE-2026-87900 (CVSS 8.1 — High): An authenticated cPanel user can alter databases owned by other accounts on the same server due to mishandled database-creation commands in WP Toolkit.
These vulnerabilities collectively present a significant risk to shared hosting environments until administrators apply patches.
The following reports contain further technical details:
[/emaillocker]