CVE-2026-87899

Summary

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

Affected Software

VendorProductVersion RangeStatus
WebProscPanel11.120.0.0 < 11.134.0.57affected
WebProscPanel11.136.0.0 < 11.136.0.41affected
WebProscPanel11.138.0.0 < 11.138.0.8affected
WebProscPanel11.134.0.57 < 11.134.0.57unaffected
WebProscPanel11.136.0.41 < 11.136.0.41unaffected
WebProscPanel11.138.0.8 < 11.138.0.8unaffected

Weaknesses

  • CWE-250: CWE-250 Execution with Unnecessary Privileges

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References