OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-87900

CRITICAL · CVSS 9.4 EPSS 0.61%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

WP Toolkit for cPanel versions 6.11.2-10794 and earlier are vulnerable to argument injection, enabling remote authenticated users to read arbitrary files and execute code across different customer accounts. This critical vulnerability poses a significant risk of unauthorized access and potential compromise of sensitive data. Hosting providers and administrators utilizing affected versions should prioritize immediate patching to mitigate the risk of exploitation.

CVE
CVE-2026-87900
Severity
CRITICAL
CVSS
9.4
EPSS
0.61%

Original NVD Description

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.