CVE-2026-87899
published 2026-09-23CVE-2026-87899: Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
PriorityP261critical9.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.58%
45.3th percentile
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | >= 11.120.0.0 < 11.134.0.57 | 11.134.0.57 |
| webpros | cpanel | >= 11.136.0.0 < 11.136.0.41 | 11.136.0.41 |
| webpros | cpanel | >= 11.138.0.0 < 11.138.0.8 | 11.138.0.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WebPros cPanel prior 11.134.0.57/11.136.0.41/11.138.0.8 privileges management
vuldb·2026-09-23·CVSS 9.4
CVE-2026-87899 [CRITICAL] WebPros cPanel prior 11.134.0.57/11.136.0.41/11.138.0.8 privileges management
A vulnerability was found in WebPros cPanel. It has been declared as very critical. Affected by this issue is some unknown functionality. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-87899. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
ghsa_unreviewed·2026-09-23
CVE-2026-87899 [CRITICAL] CWE-250 Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
blogs_hackernews·2026-09-28·CVSS 9.8
CVE-2026-88771 [CRITICAL] ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.
Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing exotic. Mostly things nobody expected to matter anymore.
Here’s the full recap of what mattered this week.
## ⚡ Threat of the Week
Citrix
Hackernews
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
blogs_hackernews·2026-09-23
CVE-2026-87899 New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.
cPanel has released fixed versions for both, along with a fix for a third flaw in the same service, which stores each account's calendars and contacts. That third flaw lets a local user on the server read other a
2026-09-23
Published