← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

cPanel Fixes Critical Flaw Allowing Root Access and Cross-Account Database Modification

🔄 Updated 12h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • cPanel fixed a flaw allowing root code execution via CalDAV/CardDAV service.
  • A WP Toolkit bug permitted cross-account database modifications.
  • A third flaw allowed local users to read other accounts' calendar data.
  • Researcher Ali Mustafa (rz1027) is credited with discovering these flaws.

Critical Root Access Vulnerability Patched

cPanel announced on September 22 that it has patched a critical flaw in its CalDAV and CardDAV service. This vulnerability allowed any user with a cPanel hosting account to execute arbitrary code as root, leading to full control over the server. This poses a significant risk, especially for shared hosting environments where multiple customers share a single server.

WP Toolkit Bug Enabled Cross-Account Database Changes

A second significant bug was addressed in the WP Toolkit plugin, which is used for installing and managing WordPress sites. This flaw allowed a cPanel account holder to modify databases belonging to other accounts on the same server. While cPanel did not specify the extent of possible modifications or if data could be read, the potential for unauthorized data manipulation is high.

Additional Flaw in Calendar and Contact Service

cPanel also fixed a third vulnerability within the same CalDAV and CardDAV service. This flaw permitted a local user on the server to read calendar events and contacts from other accounts. Unlike the root access flaw, this bug did not allow for data modification or root access, limiting its impact to information disclosure.

Researcher Credit and Broader Context

All three vulnerabilities were discovered and reported by security researcher Ali Mustafa, known as rz1027. Mustafa has been credited with multiple cPanel and Plesk flaws since late August. This series of discoveries highlights ongoing security scrutiny of popular hosting control panels, with previous fixes including a cPanel EmailTrack root code execution flaw and Plesk Backup Manager vulnerabilities.

Update Instructions for Affected Systems

cPanel has released fixed versions for cPanel & WHM (CVE-2026-87899 and CVE-2026-68490) and the WP Toolkit. Users are advised to follow cPanel's specific update instructions for both cPanel & WHM and the wp-toolkit-cpanel package to mitigate these risks. There is no information available regarding whether the Plesk version of WP Toolkit is affected or if any of these flaws have been actively exploited.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

cPanel released fixes for a critical vulnerability in its CalDAV and CardDAV service that allowed any cPanel account holder to execute code as root, gaining full server control. Additionally, a bug in the WP Toolkit plugin was patched, which permitted account holders to alter databases belonging to other accounts.