Privilege Escalation in cPanel Affects Remote Authenticated Users
CVE-2026-87899
9.4CRITICAL
What is CVE-2026-87899?
A security flaw in cPanel permits remote authenticated users to execute arbitrary code with root privileges, potentially compromising the entire system. This vulnerability arises from improper handling of user permissions, which allows more access than intended. Administrators should take immediate action to mitigate risks associated with this exploit.
Affected Version(s)
cPanel 11.120.0.0 < 11.134.0.57
cPanel 11.136.0.0 < 11.136.0.41
cPanel 11.138.0.0 < 11.138.0.8
News Articles
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
Credit
Ali Mustafa (rz1027)
