The cPanel Root Flaw Is a Wake-Up Call for Shared Hosting
A single authentication bypass in cPanel's CalDAV service lets any hosted account run code as root — turning shared hosting into a trust nightmare. The real story isn't the bug itself, but what it reveals about the fragile architecture holding up millions of small businesses online.
The Account That Can Own Your Server
A cPanel account — the kind a small business buys for $5 a month to host a WordPress site — can now be used to run code as root on the server it lives on.
That is what the vulnerability, tracked as CVE-2026-87899, allows. The flaw sits in cPanel’s CalDAV and CardDAV service, which manages calendars and contact data. No special privileges are required. No cross-account exploits needed. If you have a cPanel login and the software is unpatched, you can take full control of the server.
The fix shipped September 22 in builds 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11. But the existence of the patch is only half the story. The other half is that this has been exploited in the wild — and not to deface websites, but to deploy Mirai malware.
Why This Hurts More Than It Should
Most discussions of cPanel bugs stop at the technical details: the affected versions, the CVE, the fix. But this vulnerability cuts to the core assumption of shared hosting.
Shared hosting works because hundreds or thousands of customers accept that their server is shared — in exchange for a price that would be impossible for them to afford alone. The operating system enforces isolation. The control panel, cPanel in this case, mediates between the provider and each customer. The security model assumes that cPanel correctly isolates one customer from another.
CVE-2026-87899 shatters that assumption. A logged-in account holder can escape the sandbox entirely. In a shared environment, every other customer on that server becomes someone else’s problem — or someone else’s attack surface.
This is not a hypothetical concern. The hosting ecosystem powers a staggering portion of the internet. Small businesses, bloggers, nonprofits, and individual developers rely on shared hosting providers. Many of those providers operate on razor-thin margins. They may not update immediately. They may not have the staffing to audit whether their servers were already compromised before applying the fix.
The Second Flaw Adds Insult to Injury
A second vulnerability, CVE-2026-87900, lives in WP Toolkit — a plugin cPanel bundles to help users install and manage WordPress sites. It lets a logged-in account holder modify databases belonging to other accounts.
cPanel has not clarified exactly what modifications are possible. It did not confirm whether data can be read, only changed. And it has not said whether the attacker needs direct access to WP Toolkit itself to trigger the bug. The ambiguity matters. If database modification includes reads, then calendar data stolen by the third vulnerability becomes a minor concern compared to whatever else sits in those databases.
WP Toolkit is also available for Plesk, another hosting control panel from the same parent company, WebPros. cPanel has not stated whether the Plesk version is affected.
A Third Vulnerability, a Smaller Problem
CVE-2026-68490 affects the same CalDAV and CardDAV service. It lets a local user on the server read other accounts’ calendar events and contacts. It does not allow modification or root escalation. It is less alarming than the other two — but it reinforces the same pattern. A single service handles sensitive cross-account data, and a bug there creates a cascading set of problems.
Together, the three flaws create a worst-case scenario for any shared hosting provider: one attacker can steal contacts and calendar data, hijack databases across accounts, and then elevate to root to do whatever they want with the entire server.
Who Is Actually at Risk?
The risk profile depends on how the provider manages updates. Enterprise hosts with automated patching pipelines will have applied the fixes within hours. Small providers — the ones running on minimal staff and legacy infrastructure — may take days or weeks.
cPanel offers no temporary workaround for servers that cannot be updated yet. That silence is worth noting. For a vulnerability that grants root access and is being actively exploited, the absence of a mitigation is a failure of crisis communication.
Even patched servers may be haunted. None of the three advisories mentions exploitation details, and none provides a way to check whether a server was compromised before the update was applied. If Mirai was deployed through this flaw, every unpatched server between August 2026 and September 22 could be a tombstone — functional, seemingly secure, but carrying malware that went undetected.
The Researcher Behind the Curtain
All three flaws were credited to Ali Mustafa, who goes by rz1027. He is not a new voice in cPanel security. Since August 27, he has disclosed at least seven cPanel and Plesk vulnerabilities, three of them jointly with a researcher known as abed1526.
Those earlier findings include a September 8 flaw in cPanel’s EmailTrack feature that also allowed root execution from a mail-enabled account. The pattern is clear: the same researcher, the same category of bug, and the same devastating impact. Each discovery adds another crack to the shared-hosting model.
Plesk, meanwhile, fixed two vulnerabilities on September 10 — one in its Backup Manager’s file restoration, another in backup header handling. Both could let a customer take over the whole server. The parallel is uncomfortable. Two competing control panels, the same class of vulnerability, the same consequences.
What Happens Next
The immediate step is updating. cPanel & WHM administrators should run the upgrade through WHM (Home / cPanel / Upgrade to Latest Version) or execute /usr/local/cpanel/scripts/upcp --force as root. The WP Toolkit update requires a separate command and a manual invocation — automatic updates may not cover it.
But the longer-term reckoning is harder. This vulnerability exposes a structural weakness that no single patch can fix. Shared hosting providers are asked to maintain an isolation boundary that their own software stack cannot reliably enforce. When the control panel — the thing that exists to mediate between customers and the server — cannot be trusted, the entire model wavers.
For the small businesses that depend on this infrastructure, the lesson is blunt. If your hosting provider has not updated, you are running your website on a machine where any neighbor can become root. There is no warning. There is no log entry in your account dashboard. The compromise happens silently, and by the time you notice something is wrong, the damage may already be done.
The cPanel vulnerabilities are a reminder that the internet’s plumbing is held together by software built by humans, reviewed by humans, and updated at the speed of human attention. This time, the flaw was found, disclosed, and fixed in a reasonable window. The question is whether the next one will be.