{"cve":"CVE-2026-87900","enrichment":{"created":"2026-09-23T22:15:11.358536+00:00","title":"Remote Authenticated File Read and Code Execution via Argument Injection in WP Toolkit for cPanel","updated":"2026-09-23T22:15:11.358550+00:00","vendors":[]},"mitre":{"cpes":[],"created":"2026-09-23T19:52:47.153000+00:00","description":"Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2026/87xxx/CVE-2026-87900.json","references":["https://support.cpanel.net/hc/en-us/articles/43597969409943"],"title":null,"updated":"2026-09-23T20:05:57.710000+00:00","vendors":[],"weaknesses":["CWE-88"]},"nvd":{"cpes":[],"created":"2026-09-23T20:17:20.613000+00:00","description":"Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-87900.json","references":["https://support.cpanel.net/hc/en-us/articles/43597969409943"],"title":null,"updated":"2026-09-23T21:17:03.717000+00:00","vendors":[],"weaknesses":["CWE-88"]},"opencve":{"changes":[{"created":"2026-09-23T20:00:00+00:00","data":[{"details":{"new":"Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.","old":null},"type":"description"},{"details":{"added":["CWE-88"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://support.cpanel.net/hc/en-us/articles/43597969409943"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"11feb0a4-bd75-4f30-a150-eab70b5c25fe"},{"created":"2026-09-23T20:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"10562fa4-5056-4c4c-9a54-0daaddb832fb"},{"created":"2026-09-23T22:30:00+00:00","data":[{"details":{"new":"Remote Authenticated File Read and Code Execution via Argument Injection in WP Toolkit for cPanel","old":null},"type":"title"}],"id":"9cc6c4b0-ed3f-48a7-8975-0ab3847de345"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2026-09-23T19:52:47.153000+00:00","provider":"mitre"},"description":{"data":"Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://support.cpanel.net/hc/en-us/articles/43597969409943"],"providers":["mitre","nvd"]},"title":{"data":"Remote Authenticated File Read and Code Execution via Argument Injection in WP Toolkit for cPanel","provider":"enrichment"},"updated":{"data":"2026-09-23T22:15:11.358550+00:00","provider":"enrichment"},"vendors":{"data":[],"providers":[]},"weaknesses":{"data":["CWE-88"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-09-23T19:52:47.153000+00:00","description":"Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-09-23T20:05:54.641000+00:00","vendors":[],"vulnrichment_repo_path":"2026/87xxx/CVE-2026-87900.json","weaknesses":[]}}