On this page
CVSS 9.4. CWE-250. CVE assigned by HackerOne. Anyone reading those numbers will flinch.
But here's the counterintuitive truth: the most dangerous thing about this vulnerability isn't the 9.4. It's a characteristic CVSS doesn't measure, and it could leave a lot of website owners stunned this afternoon.
What exactly is this vulnerability?
On September 23, 2026, according to MITRE CVE, a new cPanel vulnerability was published: CVE-2026-87899, "Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges."
In plain English: an ordinary cPanel user, with nothing more than a login to the panel (via a browser, remotely), can run arbitrary code as root on the server. The entire server, not just that user's own website.
The flaw was discovered by Ali Mustafa (rz1027) and reported through HackerOne, the well-established bug bounty platform. WebPros, cPanel's parent company, released emergency patches for the supported branches and confirmed the issue on its official support page.
About the 9.4: this is on the CVSSv4 scale, which runs slightly higher than the familiar v3. Whichever scale you use, it's CRITICAL, the highest severity rating. CISA has also confirmed that classification and rated the technical impact as "total".
Which versions are affected
cPanel runs several release branches in parallel. The vulnerability affects the main branches before the following patches:
| Branch | Affected versions | Safe patch |
|---|---|---|
| 11.138 | 11.138.0.0 → before 11.138.0.8 | 11.138.0.8 |
| 11.136 | 11.136.0.0 → before 11.136.0.41 | 11.136.0.41 |
| 11.134 | 11.134.0.0 → before 11.134.0.57 | 11.134.0.57 |
| 11.120+ | Older versions not backported | Upgrade to a supported branch |
If you're running cPanel 11.120 or earlier, you're very likely outside the automatic patch release window and need to intervene manually.
The scary part isn't the 9.4
Now for the thing I really want you to notice.
CVSS 9.4 tells you the severity, but what makes this flaw far more worrying than
the number is its attack vector: AV:N/AC:L/PR:L/UI:N.
Translation: attackable over the network, low complexity, no user interaction required. All it takes is one cPanel account, whether a low-privilege one, a former employee's, or one leaked through phishing, and root can be taken remotely.
And here's the part to stop and reread: cPanel runs most of the world's shared hosting. A single cPanel server often hosts hundreds or even thousands of accounts. An attacker only needs the weakest one. How do they get it? Buy the cheapest hosting plan available, or pull one from an old credential leak, and from there take the whole server.
The flaw falls under CWE-250: Execution with Unnecessary Privileges. Put simply, cPanel lets some operation run with more privilege than it needs. It's a classic, but still deadly, because it's a design flaw, not a misconfiguration. The patch is the only fix.
"Authenticated users": think you're safe? Not so fast
Plenty of people read "remote authenticated user" and think: "My account is secure, I've got good security, who could get in?"
That's wrong in three ways:
- You don't control your customers' accounts. If you host sites for clients, anyone who rents a plan on your server, and therefore has a cPanel account, counts as an "authenticated user." A bad actor just has to buy the cheapest plan, and if the server isn't patched, they have root.
- Credentials may have leaked long ago. Old cPanel accounts belonging to former staff, accounts for side projects you shut down: all of them are open doors if the password still works.
- CISA recorded "Exploitation: none" at publication, meaning no in-the-wild exploitation had been observed. But the lesson from every previous critical CVE is that the gap between "no PoC yet" and "mass scanning" is extremely short. Look at WordPress CVE-2026-87902 before it: probing started less than five hours after the patch. With cPanel, the most widely used hosting control panel in the world, that window could be even shorter.
What to do, in priority order
Emergency checklist for server administrators:
- Check your cPanel version immediately. Log in to WHM → Server Information → cPanel Version. Compare it with the table above.
- Update to the patched release. On the 11.138 branch, go to 11.138.0.8. On 11.136, go to 11.136.0.41. On 11.134, go to 11.134.0.57. Older versions: upgrade to at least 11.134.0.57 as soon as possible.
- If you can't patch right away, lock down accounts. Temporarily disable or restrict inactive accounts. Audit the list of cPanel accounts that are still active.
- Turn on two-factor authentication (2FA) for every cPanel/WHM account, if you haven't already. It's one of the cheapest and most effective defenses there is.
- Watch cPanel's support page and security channels for updates. More detail on the exploitation mechanism may emerge in the coming days.
What security news never tells you
One observation from years of writing about vulnerabilities: most people read news like this, check whether their server is affected, update, and forget about it. And that's the right thing to do.
But if you run hosting for clients, there's a deeper question worth asking yourself: "Does my server still have accounts I don't remember exist?"
When you have hundreds of accounts on one machine, one of them getting compromised, whether through a vulnerability or stale credentials, is a matter of when, not if. Today's flaw is CVE-2026-87899. Next month it'll be another CVE. The core problem isn't chasing every patch; it's building an operating process in which updating stops being a burden.
A practical question: do you know exactly which cPanel version your server is running? If the answer is "probably around…" or "let me check," then the biggest vulnerability isn't the CVE.
At An Tran Solutions I offer regular security review and hardening for websites and hosting infrastructure. If you want a second pair of eyes, or simply want to be sure nothing slipped through, send me a message.

