A vulnerability in cPanel's CalDAV and CardDAV services permits unauthorized code execution as root, enabling full server control for any cPanel-hosted account This article explores vulnerability cpanel. . Additionally, a flaw in the WP Toolkit plugin, utilized for installing and managing WordPress sites, allows an account holder to alter databases belonging to other users.

CPanel has released updated versions to address all three vulnerabilities within the system, which includes storing each user's calendars and contacts. The third flaw, which allows a local user on the server to read but not modify or gain root access to other accounts' calendars and contacts, has also been fixed.

CPanel indicates that a logged-in cPanel user can perform database modifications in other accounts, but it does not specify what changes are possible, whether data from other accounts can be accessed, or if the user requires access to WP Toolkit itself. For WP Toolkit (CVE-2026-87900), upgrade to version 6.11.3 or later using this command: bash <(curl https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -O - https://wp-toolkit.plesk.com/cPanel/installer.sh) --version 6.11.3. The calendar issues affect versions 120 and later, but cPanel only lists fixed builds for the 134, 136, and 138 release lines and for WP Squared.

CPanel provides no temporary solution for servers that cannot be updated yet.