← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 15:18via Cyber Security News

New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts

Brief

cPanel has patched three newly disclosed security vulnerabilities that threaten tenant isolation on shared-hosting servers, including a permissions flaw that exposes other users’ calendars and contacts.

The September 22, 2026, security release addresses CVE-2026-68490 alongside a root privilege-escalation bug and a WP Toolkit cross-account database vulnerability, making immediate updates essential for hosting providers and server administrators.

cPanel Vulnerability

Tracked as CVE-2026-68490, the primary vulnerability stems from incorrect permissions in cPanel’s CalDAV and CardDAV functionality. A local user with access to the same server could exploit the weakness to read calendar events and contact information belonging to other cPanel accounts.

The flaw breaks a key security boundary in multi-tenant environments, where customers expect their account data to remain isolated.

Read more on Cyber Security News