Critical cPanel Flaw Lets Hosting Customers Seize Full Server Control
cPanel has disclosed a critical flaw in its CalDAV and CardDAV service, the feature that stores each account's calendars and contacts, that could let any hosting account holder run code as root and gain full control of the server. No special privileges are needed beyond having a standard account, meaning that on shared hosting servers, any paying customer, or anyone who obtains a customer's login, could exploit it.
A second flaw affects the WP Toolkit plugin used to install and manage WordPress sites, allowing an account holder to alter databases belonging to other accounts on the same server. cPanel has not detailed exactly what changes are possible or whether data from other accounts could also be read. A third, related flaw in the calendar and contacts service allows a local user to view (but not modify) other accounts' calendar and contact data. cPanel has released fixed versions for all three issues.
These vulnerabilities were reported by a researcher who has now been credited with at least seven similar flaws in cPanel and Plesk products since late August, including a root-access bug in cPanel's EmailTrack feature and two Plesk Backup Manager flaws disclosed in early September. None of the issues have been confirmed as actively exploited, and none currently appear in CISA's Known Exploited Vulnerabilities catalog, but the pattern of repeated critical findings across hosting control panels is notable.