HostRite News

Cloud Hosting Domain Names WordPress And Service Updates.

Advertisement

Critical cPanel Flaw Lets Hosting Accounts Run as Root

Hooded hacker at a laptop with red skull screen bold headlines tout hosting drama run code as root with cpanel hepsia and hostrite branding in the background

New cPanel Flaw Lets a Hosting Account Run Code as Root

cPanel root vulnerability

A newly disclosed cPanel root vulnerability demonstrates just how serious a security flaw in a web hosting control panel can become.

The vulnerability, identified as CVE-2026-87899, affects cPanel’s CalDAV and CardDAV functionality. According to cPanel’s own security advisory, an authenticated cPanel account holder can exploit the flaw to escalate privileges and execute code as the server’s root user. Successful exploitation gives the attacker full control of the affected server.

For people who aren’t familiar with server terminology, “root” essentially means the highest level of administrative control on a Linux server. This isn’t simply a vulnerability that could affect one website or one hosting account. Successful exploitation could give an attacker control over the server itself.

The vulnerability was publicly disclosed by cPanel on September 22, 2026, with The Hacker News reporting additional details on September 23.

There is also an important distinction for HostRite Cloud Hosting customers:

HostRite’s cloud webhosting platform does not use cPanel. We use the Hepsia Control Panel.

Therefore, this specific cPanel vulnerability does not apply to HostRite’s Hepsia-based cloud hosting platform. That conclusion follows from the vulnerability being identified specifically in cPanel’s CalDAV/CardDAV functionality, rather than being a general Linux or web-hosting vulnerability.

Let’s take a closer look at what happened, what the vulnerability could allow, what cPanel administrators need to do, and why the difference between cPanel and HostRite’s Hepsia platform matters.


What Is the New cPanel Root Vulnerability?

The primary vulnerability is tracked as:

CVE-2026-87899

It exists in cPanel’s CalDAV and CardDAV functionality.

CalDAV and CardDAV are technologies associated with calendar and contact information. However, the important part of this story isn’t what those services normally do.

It’s what the vulnerability can allow an attacker to do.

cPanel’s September 22 security advisory states that an authenticated cPanel account holder can escalate privileges through this functionality. Successful exploitation results in code executing as root, giving the attacker full control of the server.

The Hacker News reports that cPanel listed no additional prerequisite for the root vulnerability beyond having an account. On a shared hosting server where individual hosting accounts are sold to customers, that makes the potential impact particularly significant.

Why Root Access Is Such a Serious Problem

Web hosting servers commonly contain multiple customer accounts.

Under normal circumstances, one hosting customer shouldn’t have administrative control over another customer’s account.

That’s one of the fundamental boundaries shared hosting is supposed to maintain.

A customer should be able to work with their own:

  • Website files
  • Databases
  • Email
  • Domains
  • Applications

They should not be able to take administrative control of the entire server.

A cPanel root vulnerability changes that equation.

Root is the highest-privileged administrative account on a typical Linux server. If an attacker successfully executes code with root privileges, the security boundary separating an ordinary hosting account from the underlying server has been defeated.

cPanel itself describes the impact plainly: successful exploitation gives the attacker full control of the server.

For a shared hosting provider, that’s substantially more serious than a vulnerability confined to one customer’s website.

One Hosting Account Could Potentially Become a Server-Level Problem

This is one reason the new vulnerability deserves attention from hosting providers.

According to The Hacker News, cPanel’s advisory lists having an authenticated account as the requirement for exploiting CVE-2026-87899. The publication notes that on a shared server, this could potentially mean a legitimate hosting customer—or someone who obtains a customer’s credentials—could attempt to exploit the vulnerability.

That is an important difference from an attack that first requires someone to obtain the hosting provider’s root password.

The vulnerability creates a potential path from an ordinary authenticated cPanel account to root-level code execution.

The exact technical exploitation process isn’t necessary for everyday hosting customers to understand.

The important point is the privilege jump:

Normal hosting account → root-level server control

That is why cPanel has released patched versions and instructed administrators to update.

Bright neon ad collage promoting hostrite cloud hosting with'Does Not Use cPanel' and Hepsia Control Panel on a laptop image.
Hostrite cloud hosting does not use cpanel

HostRite Cloud Hosting Does Not Use cPanel

This is where the story becomes directly relevant to HostRite News readers and HostRite customers.

HostRite’s cloud webhosting platform uses Hepsia—not cPanel.

CVE-2026-87899 is specifically identified by cPanel as a vulnerability in cPanel’s CalDAV/CardDAV functionality.

Because HostRite’s cloud platform does not run cPanel, the affected cPanel component is not present there.

Consequently, this specific CVE-2026-87899 cPanel vulnerability does not affect HostRite’s Hepsia-based cloud hosting platform.

That distinction should not be interpreted as saying any hosting platform is universally “immune” to security vulnerabilities. No responsible hosting provider should make that blanket claim.

Instead, the accurate statement is:

HostRite’s cloud hosting platform is not affected by this specific cPanel vulnerability because HostRite uses Hepsia rather than cPanel.

That’s an important distinction, particularly when vulnerability headlines refer broadly to “hosting accounts” or “hosting servers.”

The affected software matters.

Hepsia and cPanel Are Different Control Panels

To everyday website owners, hosting control panels can appear to perform many of the same basic jobs.

Both are intended to provide a graphical interface between customers and their hosting environment.

However, Hepsia and cPanel are separate software platforms.

HostRite customers use Hepsia to manage common hosting functions rather than using cPanel.

That includes everyday areas such as domains, email, website files and databases.

Therefore, a vulnerability specifically located inside cPanel does not automatically become a vulnerability in Hepsia simply because both products are hosting control panels.

Think about two different web browsers.

A security vulnerability discovered in a specific component of one browser doesn’t automatically mean every other browser contains the same vulnerability.

The same basic principle applies here.

This Is Not the First Recent cPanel Root Vulnerability

The latest disclosure also arrives after other significant cPanel vulnerabilities.

On September 8, 2026, cPanel disclosed CVE-2026-67401, an SQL injection vulnerability involving its EmailTrack functionality.

According to cPanel, an authenticated account holder with mail-related privileges could create arbitrary files on the server through EmailTrack. Successful exploitation could then result in code execution as root and full control of the server.

That vulnerability affected all supported cPanel & WHM versions at the time of disclosure, although patched builds were released.

Before that, cPanel disclosed another serious vulnerability on August 27, 2026.

CVE-2026-65643 involved cPanel’s domain-parking functionality.

An authenticated account holder capable of adding parked or add-on domains could create arbitrary files on the server. Successful exploitation could lead to root code execution and full control of the server, including the accounts, websites and databases hosted there.

These are separate vulnerabilities involving different parts of cPanel.

They shouldn’t be treated as one flaw.

However, together they reinforce why hosting providers need to keep control-panel software and related server components updated.

Three Newly Disclosed cPanel Security Problems

The September 22 disclosure actually covers more than CVE-2026-87899.

Three vulnerabilities are involved in the latest round of cPanel security updates.

VulnerabilityAffected AreaPotential Impact
CVE-2026-87899CalDAV/CardDAVAuthenticated account holder can execute code as root
CVE-2026-87900WP ToolkitAuthenticated cPanel user can modify databases belonging to other accounts
CVE-2026-68490CalDAV/CardDAVLocal user can read other accounts’ calendar events and contacts

The first vulnerability is the most severe in terms of server control because cPanel says successful exploitation results in root-level code execution.

The other two shouldn’t be ignored.

WP Toolkit Vulnerability Could Cross Account Boundaries

The second vulnerability, CVE-2026-87900, affects WP Toolkit.

WP Toolkit is used for installing and managing WordPress websites.

According to The Hacker News, the vulnerability concerns how WP Toolkit handles commands used to create databases. A logged-in cPanel user could potentially perform database modifications in other accounts.

The reporting notes some important unknowns.

cPanel did not specify exactly what database modifications could be made, whether information belonging to those other accounts could also be read, or whether exploitation requires access to WP Toolkit itself.

Those limitations matter.

We shouldn’t assume capabilities beyond what the vendor has disclosed.

The confirmed issue is the ability to make database modifications across account boundaries.

Another Flaw Could Expose Calendar and Contact Information

The third vulnerability is CVE-2026-68490.

This issue also involves cPanel’s CalDAV and CardDAV functionality.

Rather than providing root access, it can allow a local server user to read calendar events and contacts belonging to other accounts. The affected information cannot be changed through this vulnerability, according to the reporting.

Again, this demonstrates why account isolation matters on shared hosting systems.

One customer’s account shouldn’t ordinarily have access to another customer’s private information.

Which cPanel Versions Are Affected?

For CVE-2026-87899, cPanel identifies cPanel & WHM version 120 and later as affected.

The patched releases listed by cPanel are:

Release LinePatched Version
11.13411.134.0.57 or later
11.13611.136.0.41 or later
11.13811.138.0.8 or later
WP Squared11.138.1.11 or later

Administrators responsible for cPanel servers should follow cPanel’s current vendor guidance rather than relying solely on a third-party article for patch decisions.

Sysadmin updating cpanel whm on a monitor in a data center with a neon sign urging updates in the background
Cpanel administrators should update

cPanel Administrators Should Update

cPanel’s recommendation is straightforward:

Update to the latest patched version.

The Hacker News reports that administrators can update cPanel & WHM through:

WHM → Home → cPanel → Upgrade to Latest Version

The vendor also provides its normal command-line update process for administrators managing servers directly.

The important message for everyday hosting customers is simpler.

If your hosting provider uses cPanel, the provider or server administrator should be applying the vendor’s security update.

Customers on managed shared hosting generally don’t control the underlying WHM installation themselves.

WP Toolkit Needs Its Own Update

The WP Toolkit issue is separate from the cPanel CalDAV/CardDAV root vulnerability.

According to the September 23 report, WP Toolkit 6.11.2-10794 and older are affected by CVE-2026-87900.

The fixed version is:

WP Toolkit 6.11.3 or later

Because WP Toolkit is installed as its own package, it has its own update process rather than simply being treated as part of the main cPanel update.

Administrators who use both cPanel and WP Toolkit therefore need to pay attention to both sets of updates.

Is This cPanel Vulnerability Being Actively Exploited?

As of the reporting on September 23, 2026, there was no indication in the cited advisories that these three newly disclosed vulnerabilities were being exploited in the wild.

The Hacker News also reported that the vulnerabilities were not present in CISA’s Known Exploited Vulnerabilities catalog when it checked on September 23.

However, that does not prove exploitation hasn’t occurred.

It means there was no confirmed exploitation information in those sources at the time of publication.

That’s an important distinction with newly disclosed vulnerabilities.

Security information can change quickly.

Sysadmin updating cpanel whm on a monitor in a data center with a neon sign urging updates in the background
Cpanel administrators should update

HostRite Customers Don’t Need a cPanel Patch for This Vulnerability

For HostRite Cloud Hosting customers, the situation is different.

Because our cloud webhosting platform uses Hepsia instead of cPanel, HostRite isn’t running the affected cPanel CalDAV/CardDAV component on that platform.

Therefore, there is no cPanel installation on the HostRite cloud platform that needs to be upgraded to address CVE-2026-87899.

Likewise, the cPanel-specific EmailTrack vulnerability CVE-2026-67401 and cPanel domain-parking vulnerability CVE-2026-65643 concern cPanel components rather than Hepsia.

Again, that statement is deliberately specific.

HostRite is unaffected by these particular cPanel vulnerabilities because our cloud hosting platform doesn’t use cPanel.

It does not mean Hepsia, HostRite or any other hosting technology can never have a vulnerability.

Security requires continuous maintenance regardless of which control panel a provider chooses.

Why HostRite Uses the Hepsia Control Panel

HostRite’s choice of Hepsia isn’t simply about avoiding cPanel.

Hepsia is the hosting-management environment we provide to customers on our cloud hosting platform.

Instead of presenting customers with cPanel, HostRite uses Hepsia to provide access to the tools needed for ordinary hosting management.

For an everyday website owner, the important part is straightforward:

You can manage your hosting without cPanel.

This latest security incident also illustrates an often-overlooked benefit of software diversity.

When a vulnerability is confined to one particular product or component, systems that don’t run that affected software don’t automatically inherit the same flaw.

In this case, cPanel identifies the vulnerable functionality as its own CalDAV/CardDAV implementation.

HostRite’s Hepsia-based cloud platform therefore falls outside the affected product scope.

Different Software Does Not Mean Security Can Be Ignored

There is an important security lesson here for every hosting provider—including HostRite.

Using Hepsia rather than cPanel doesn’t eliminate the need for security work.

Hosting infrastructure contains many layers:

Operating systems

Web servers

Databases

Email services

Control panels

Website applications

WordPress

Plugins

Themes

Customer passwords

Every layer needs attention.

A provider can avoid a cPanel-specific vulnerability by not using cPanel, but that doesn’t make every other component invulnerable.

Similarly, customers have responsibilities of their own.

WordPress should be updated.

Plugins should be maintained.

Unused software should be removed.

Strong passwords should be used.

Two-factor authentication should be enabled where available.

Backups remain important.

Security works best when the hosting provider and website owner both maintain the parts they control.

What This Means for Everyday Website Owners

If you’re reading headlines about a “hosting account taking over an entire server,” it’s understandable to wonder whether your website is affected.

The first question to ask is:

Does my hosting provider use the affected software?

If your provider uses cPanel, the provider should verify that the server has been updated to a patched version.

If you’re running your own cPanel server or VPS, you should review cPanel’s advisory and ensure the appropriate updates have been installed.

If you’re using HostRite’s Hepsia-based cloud hosting platform, this specific cPanel vulnerability isn’t applicable because the affected cPanel software isn’t used on that platform.

That is the key takeaway for HostRite customers.

Neon sign reads'cPanel ROOT VULNERABILITY FAQ' beside a laptop showing HostRite cloud hosting on a desk.
Cpanel root vulnerability faq

cPanel Root Vulnerability FAQ

What is CVE-2026-87899?

CVE-2026-87899 is a vulnerability in cPanel’s CalDAV/CardDAV functionality that can allow an authenticated cPanel account holder to escalate privileges and execute code as the root user.

How serious is the vulnerability?

Successful exploitation gives the attacker root-level code execution and full control of the affected server, according to cPanel.

Does an attacker already need a hosting account?

cPanel describes the vulnerability as exploitable by an authenticated cPanel account holder. The Hacker News reports that no additional requirement was listed in the advisory.

Does the vulnerability affect shared hosting?

It can affect cPanel & WHM systems running affected versions. On shared hosting, the concern is especially significant because multiple customer accounts may reside on the same server.

Which cPanel versions are affected?

cPanel says cPanel & WHM version 120 and later are affected by CVE-2026-87899. Patched builds have been released for the currently listed release lines.

Has cPanel fixed the vulnerability?

Yes. cPanel has released patched versions and recommends updating to the latest patched release.

Is HostRite Cloud Hosting affected by CVE-2026-87899?

HostRite’s cloud hosting platform does not use cPanel; it uses Hepsia. Because CVE-2026-87899 is specifically a vulnerability in cPanel’s CalDAV/CardDAV functionality, this particular vulnerability does not affect HostRite’s Hepsia-based cloud hosting platform.

Does that mean Hepsia can never have a security vulnerability?

No. No complex software platform should be described as permanently immune from vulnerabilities. The accurate claim is that this specific cPanel vulnerability doesn’t affect HostRite’s Hepsia platform because HostRite isn’t running the affected cPanel software.

What is CVE-2026-87900?

It is a separate vulnerability involving WP Toolkit that can allow a logged-in cPanel user to modify databases belonging to other hosting accounts. WP Toolkit 6.11.3 or later contains the fix identified in the current reporting.

What is CVE-2026-68490?

It is another CalDAV/CardDAV vulnerability that can allow a local user to read other accounts’ calendar events and contacts. Unlike CVE-2026-87899, the disclosed impact does not include root access.

Was cPanel affected by other recent root vulnerabilities?

Yes. cPanel disclosed CVE-2026-67401 involving EmailTrack on September 8 and CVE-2026-65643 involving domain parking on August 27. Both could lead to root-level code execution under their respective exploitation conditions.

HostRite News: What Customers Should Take Away From This

The latest cPanel security disclosure is a strong reminder that a hosting control panel isn’t merely the dashboard customers see after logging in.

It is powerful server software.

When a vulnerability allows an ordinary hosting account to cross the boundary between customer access and root-level administrative access, the potential consequences can extend far beyond a single website.

CVE-2026-87899 demonstrates exactly that risk.

cPanel confirmed on September 22 that the vulnerability affects its CalDAV/CardDAV functionality and that successful exploitation can result in root code execution and full server control. Patched releases are available, and cPanel administrators should update according to the vendor’s guidance.

For HostRite Cloud Hosting customers, however, there is an equally important part of this story:

HostRite Cloud Hosting does not use cPanel on our cloud webhosting platform. We use the Hepsia Control Panel.

That means CVE-2026-87899 does not affect HostRite’s Hepsia-based cloud hosting platform because the vulnerable cPanel software isn’t part of that platform.

The same principle applies to the recently disclosed vulnerabilities specifically involving cPanel’s EmailTrack and domain-parking functionality.

Security is never something a hosting provider gets to declare finished. New vulnerabilities will continue to be discovered across operating systems, applications, plugins, control panels and other software.

But when a vulnerability makes headlines, the first thing that matters is determining what software is actually affected.

In this case, the answer is cPanel.

HostRite’s cloud webhosting platform runs Hepsia instead.

HostRite News

Promotional banner for hostrite cloud hosting highlighting a 30 day free trial and key message
Hostrite news what customers should take away from this try us 30 days for free
author avatar
Thomas B. Administrator
Thomas B I am Admin of HostRite Cloud Hosting and authtor at HostRite News. I am a bonified tech enthusiast. Love hosting tech advances and especially WordPress.
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x