PT-2026-97063 · Cpanel · Cpanel

·

CVE-2026-87899

·

Published

2026-09-22

·

Updated

2026-09-25

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions cPanel/WHM versions 120 through 11.133.x cPanel/WHM versions 11.134.0 through 11.134.0.56 cPanel/WHM versions 11.136.0 through 11.136.0.40 cPanel/WHM versions 11.138.0 through 11.138.0.7 WP2 versions prior to 11.138.1.11
Description Remote authenticated users can escalate privileges through the CalDAV and CardDAV functionality. This issue allows an authenticated account holder to execute arbitrary code with root privileges, which can lead to full server compromise.
Recommendations Update cPanel/WHM to version 11.134.0.57 or newer for the 11.134 branch. Update cPanel/WHM to version 11.136.0.41 or newer for the 11.136 branch. Update cPanel/WHM to version 11.138.0.8 or newer for the 11.138 branch. Update WP2 to version 11.138.1.11 or newer.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87899

Affected Products

Cpanel