Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-87899: cPanel lets remote users run code as root

CVE-2026-87899 · published 16 days ago
Summary

cPanel can be tricked by a signed‑in user to run any program with the highest system rights. This could let an attacker take full control of the server. Apply the latest cPanel updates and restrict remote access to trusted users only.

What to do
  • Update webpros cpanel to version 11.134.0.57 or later.
Affected software
VendorProductAffected versions
webpros cpanel < 11.134.0.57
Original advisory text
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-250Execution with Unnecessary Privileges
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-87899 · MITRE
Track software like this
Free during beta