cPanel says a calendar login is enough to take the whole server
Vulnerability Management

cPanel says a calendar login is enough to take the whole server

Mathew Potter

Security Analyst

September 23, 2026

cPanel said Tuesday that a calendar service is enough. CVE-2026-87899 sits in CalDAV and CardDAV. Anyone with a hosting account can run code as root and take the whole machine. Full control is their phrase. On a shared box that sells accounts to the public, that is any customer. It is also anyone who stole a customer's login. The Hacker News carried it this morning. We already wrote the Acronis cPanel plugin last week. This is the panel itself.

What cPanel actually patched

Three holes, two products. The root one is 87899, cPanel and WHM version 120 and later. A logged-in account, no extra privilege named in the note. Fixed builds: 11.134.0.57 or later, 11.136.0.41 or later, 11.138.0.8 or later, WP Squared 11.138.1.11 or later. The same update covers CVE-2026-68490, a local read of other accounts' calendars and contacts. No write, no root, still a neighbour's address book.

WP Toolkit is separate. CVE-2026-87900 lets a logged-in cPanel user change databases that belong to other accounts. Fixed in Toolkit 6.11.3 or later. The panel upgrade does not move that package for you. cPanel has not said whether the Plesk build of Toolkit is in scope.

No workaround in the advisory. No hunt recipe. Not on CISA's exploited list as of this morning. Ali Mustafa (rz1027) reported all three. He has a pile of cPanel and Plesk credits since late August, including EmailTrack to root on September 8 and Plesk Backup Manager holes on September 10 that could also take the server. The week is the hosting stack, not one CVE.

Why a shop in Alberta should care

Plenty of contractor sites, law firms, and small retailers still live on a cPanel share they bought from a reseller. The site looks fine. The calendar sync on a phone is how the account stays "used." If that account can become root, every other tenant on the box is in the blast, including the backups that sit next to the sites. Last week's Acronis plugin (CVE-2026-87886) was already used. This one has no public use in the reporting we have. The lesson is the same: the panel is a computer, and a customer login is enough.

If you are the host, a stolen mailbox password is now a server problem. If you are the tenant, ask the host which build they are on. Do not take "we patch monthly" as an answer this week.

What we would do today

  • Hosts: WHM, Home / cPanel / Upgrade to Latest Version, or upcp --force as root. Write the build. 134 needs .57 or later. 136 needs .41. 138 needs .8. Then check WP Toolkit on its own and move it to 6.11.3 or later.
  • Tenants: ticket the host for those numbers. If they cannot name a build, that is the finding.
  • Do not disable calendars as a hobby fix. cPanel did not offer a workaround. The update also repairs calendar and contact permissions on existing accounts.
  • If you run Plesk instead, finish last week's Backup Manager note. Do not assume Toolkit is clean because the cPanel advisory is silent on Plesk.

Bottom line

A calendar service that becomes root is not a mail feature. Forensic Five reviews the panel build, who can log in, and whether the copies sit on the same box. From St. Albert, Alberta. Update the trains that have a build. Then go look at the F5 and the WordPress site, because those two also landed overnight.

Tags

cPanel CVE-2026-87899 hosting CalDAV

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.