New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Security

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News · Sep 23, 2026

Back to News
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
Security September 23, 2026

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.