Ethical Hacking News
A recent security vulnerability has been discovered in cPanel, a widely used web hosting control panel, that allows a hosting account user to run code as root and take full control of the server. This devastating flaw, disclosed by cPanel on September 22, 2026, has the potential to be exploited by malicious actors. In this article, we will delve into the details of the vulnerability, its impact, and the steps that can be taken to update and secure systems.
A recent security vulnerability has been discovered in cPanel, allowing a hosting account user to run code as root and take full control of the server. Two additional bugs, CVE-2026-87899 and CVE-2026-87900, have been identified, affecting the CalDAV and CardDAV service and the WP Toolkit plugin. A third vulnerability, CVE-2026-68490, allows a local user to read other accounts' calendar events and contacts. Fixed versions of the vulnerabilities have been released, but updating cPanel and WHM, as well as WP Toolkit, can be complex and time-consuming. Users who cannot update their servers are left vulnerable to exploitation, highlighting the importance of regular software updates and cybersecurity.
A recent security vulnerability has been discovered in cPanel, a widely used web hosting control panel, that allows a hosting account user to run code as root and take full control of the server. This devastating flaw, disclosed by cPanel on September 22, 2026, has left many in the cybersecurity community on high alert, as it has the potential to be exploited by malicious actors.
The vulnerability, identified as CVE-2026-87899, is related to cPanel's CalDAV and CardDAV service, which is used to manage contact lists and calendar events. According to cPanel, the flaw allows a logged-in account holder to run code as root, effectively granting them full access to the server. This means that an attacker could potentially gain control of the entire server, including sensitive data and systems.
However, this is not the only vulnerability discovered in cPanel. A second bug, identified as CVE-2026-87900, affects the WP Toolkit plugin, which is used to install and manage WordPress sites. This bug allows a logged-in cPanel user to change databases in other accounts, potentially allowing them to access sensitive data and systems.
A third vulnerability, identified as CVE-2026-68490, is related to cPanel's CalDAV and CardDAV service and allows a local user on the server to read other accounts' calendar events and contacts. While this flaw does not allow for root access, it still poses a significant risk to sensitive data.
The good news is that cPanel has released fixed versions for all three vulnerabilities. However, the process of updating cPanel and WHM, as well as WP Toolkit, can be complex and time-consuming, especially for those without technical expertise.
To update cPanel & WHM, users can follow the instructions provided by cPanel, which include running a script to update the software. For WP Toolkit, users can update to version 6.11.3 or later using a specific command.
Despite the availability of fixed versions, cPanel has acknowledged that there are no temporary workarounds for servers that cannot be updated yet. This means that users who are unable to update their servers are left vulnerable to exploitation.
The discovery of these vulnerabilities highlights the importance of regular software updates and the need for organizations to prioritize cybersecurity. As the threat landscape continues to evolve, it is essential that individuals and organizations take proactive steps to protect themselves from vulnerabilities like the one discovered in cPanel.
In conclusion, the recent vulnerability discovered in cPanel is a stark reminder of the importance of cybersecurity and the need for organizations to stay vigilant. By understanding the risks associated with this vulnerability and taking steps to update and secure their systems, individuals and organizations can help protect themselves from exploitation.
Related Information:
https://www.ethicalhackingnews.com/articles/New-cPanel-Flaw-Exposed-A-Devastating-Vulnerability-That-Allows-Root-Access-and-Full-Server-Control-ehn.shtml
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html
https://nvd.nist.gov/vuln/detail/CVE-2026-87899
https://www.cvedetails.com/cve/CVE-2026-87899/
https://nvd.nist.gov/vuln/detail/CVE-2026-87900
https://www.cvedetails.com/cve/CVE-2026-87900/
https://nvd.nist.gov/vuln/detail/CVE-2026-68490
https://www.cvedetails.com/cve/CVE-2026-68490/
Published: Wed Sep 23 08:43:23 2026 by llama3.2 3B Q4_K_M