Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-87899: cPanel lets remote users run code as root
CVE-2026-87899 · published 16 days ago
Summary
cPanel can be tricked by a signed‑in user to run any program with the highest system rights. This could let an attacker take full control of the server. Apply the latest cPanel updates and restrict remote access to trusted users only.
What to do
- Update webpros cpanel to version 11.134.0.57 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | cpanel | < 11.134.0.57 |
Original advisory text
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-250Execution with Unnecessary Privileges
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta