Threat Intelligence

Critical cPanel Flaw Lets Hosting Customers Seize Full Server Control

The Hacker News · 23 Sept 2026
Key Takeaway If your business or website host uses cPanel or WP Toolkit, confirm with your hosting provider that these patches have been applied, as unpatched shared servers put every account on them at risk.

cPanel has disclosed a critical flaw in its CalDAV and CardDAV service, the feature that stores each account's calendars and contacts, that could let any hosting account holder run code as root and gain full control of the server. No special privileges are needed beyond having a standard account, meaning that on shared hosting servers, any paying customer, or anyone who obtains a customer's login, could exploit it.

A second flaw affects the WP Toolkit plugin used to install and manage WordPress sites, allowing an account holder to alter databases belonging to other accounts on the same server. cPanel has not detailed exactly what changes are possible or whether data from other accounts could also be read. A third, related flaw in the calendar and contacts service allows a local user to view (but not modify) other accounts' calendar and contact data. cPanel has released fixed versions for all three issues.

These vulnerabilities were reported by a researcher who has now been credited with at least seven similar flaws in cPanel and Plesk products since late August, including a root-access bug in cPanel's EmailTrack feature and two Plesk Backup Manager flaws disclosed in early September. None of the issues have been confirmed as actively exploited, and none currently appear in CISA's Known Exploited Vulnerabilities catalog, but the pattern of repeated critical findings across hosting control panels is notable.

cPanel vulnerability web hosting security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.